Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

There is a storage xss in the add module of friendly links in Taocms3.0.2. #30

Open
k0xx11 opened this issue Feb 19, 2022 · 0 comments
Open

Comments

@k0xx11
Copy link

k0xx11 commented Feb 19, 2022

  • Payload: <script>alert(documnet.cookie)</script>

Click on the left link module, and then click add

image

Enter our payload and click submit

image

Found that payload has been executed

image

Back to the home page, because it is a friendly link, the front desk is also affected.

image

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant