jeecms v9.3 has a stroed xss vulnerability

An issue was discovered in jeecms v9.3 There is a stored XSS attacks vulnerability which allows remote attackers to inject arbitrary web script or HTML.

poc

<script>alert(document.cookie)</script>

Vulnerability trigger point
http://localhost//jeeadmin/jeecms/index.do#/content/update?type=update&id=130&noce_str=F3BR4K6
1.logged as admin
jeecms v9.3 has a stroed xss vulnerability
2.Choose this part
jeecms v9.3 has a stroed xss vulnerability
3.Click the green button to enter this page and insert code

jeecms v9.3 has a stroed xss vulnerability
4.Submit and view homepage
jeecms v9.3 has a stroed xss vulnerability

相关文章:

  • 2022-12-23
  • 2022-12-23
  • 2021-12-26
  • 2022-12-23
  • 2021-11-23
  • 2021-10-28
  • 2021-09-10
猜你喜欢
  • 2021-09-28
  • 2022-12-23
  • 2022-02-07
  • 2021-07-08
  • 2021-04-18
  • 2021-07-22
相关资源
相似解决方案