Visit the CMS home page and find that the JS code for the article content section is
BLUDIT CMS xss
Log on in the background, there is an article release module
BLUDIT CMS xss
You can see the successful pop-up window, execute the JS code, and prove an XSS vulnerability
BLUDIT CMS xss

Second XSS
Login background, add user module
BLUDIT CMS xss

User name input content does not do any filtering, new user name:
BLUDIT CMS xss

相关文章:

  • 2021-09-23
  • 2021-07-25
  • 2021-12-12
  • 2022-01-06
  • 2022-02-03
  • 2022-02-13
  • 2021-06-16
  • 2021-05-13
猜你喜欢
  • 2021-07-07
  • 2021-06-24
  • 2022-12-23
  • 2021-10-18
  • 2021-05-20
  • 2022-12-23
相关资源
相似解决方案