-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Open
Description
Vulnerability Product:ForestBlog
Vulnerability version: all
Vulnerability type: Stored XSS
Vulnerability Details:
the Stored XSS payload could let admin causes disclosure of cookies、root path of websites、variables of PHP and stuff
-
Login link: http://forestblog.liuyanzhao.com/login
I registered my own account here
Account: linkk
Password: linkk

-
When writing the article title or content, enter<script>alert (document. cookie)</script>
Click to publish

Discovered that xss was triggered
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
