Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jpress后台模板-板块存在存储型XSS #183

Open
longicron opened this issue Apr 2, 2023 · 1 comment
Open

jpress后台模板-板块存在存储型XSS #183

longicron opened this issue Apr 2, 2023 · 1 comment

Comments

@longicron
Copy link

jpress后台模板-板块存在存储型XSS
文字内容输入payload:<sCrIpT>alert(2)</sCrIpT>
1
每次打开模板-板块页面均可弹窗
2

@longicron
Copy link
Author

以上xss漏洞在后台写文章预览时可触发
3
4

以上xss漏洞在门户初始化文章列表时也可触发
5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant