taocms icon indicating copy to clipboard operation
taocms copied to clipboard

There is a storage type cross site scripting attack at "Management column"(Column administrator authority)

Open liangyueliangyue opened this issue 3 years ago • 0 comments

First, we enter the background and use the column administrator admin we created: image Let's click "add article" on the left: image Insert xss payload at the title :

Return to the background management page,Let's click "edit article" on the left: image

Come back to the front page,Because it is the title of the article, the front desk is also affected image

liangyueliangyue avatar Dec 09 '21 12:12 liangyueliangyue