75 Star 125 Fork 65

快乐源泉 / tpcms

 / 详情

XSS storage vulnerability exists in tpcms v3.2 management system

待办的
创建于  
2021-07-02 14:24

Logging into the management system of tpcms v3.2 (admin/admin888), in the "System Settings"-"Site Configuration"-"Bottom Information"(or "Phone"), entering XSS payload and save it. Open the front-site and you can see the pop-up window caused by the XSS payload.

URL:
http://IP/index.php/Admin/Index/index.html

Payload:

<script>alert('hello ');</script>

Image description

Image description

Image description

Image description

This vulnerability can be used in conjunction with the XSS platform. The attacker enters the malicious payload in the corresponding text box. Whenever the visitor visits the TPCMS, the visitor's information can be sent to the XSS platform.It can be used to Phising or something else.

Image description

评论 (0)

xrun 创建了任务
xrun 关联仓库设置为快乐源泉/tpcms
展开全部操作日志

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(1)
PHP
1
https://gitee.com/happy_source/tpcms.git
git@gitee.com:happy_source/tpcms.git
happy_source
tpcms
tpcms

搜索帮助