Skip to content

There is a storage xss in the add module of friendly links in Taocms3.0.2. #30

@k0xx11

Description

@k0xx11
  • Payload: <script>alert(documnet.cookie)</script>

Click on the left link module, and then click add

image

Enter our payload and click submit

image

Found that payload has been executed

image

Back to the home page, because it is a friendly link, the front desk is also affected.

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions