MiniCMS icon indicating copy to clipboard operation
MiniCMS copied to clipboard

Found xss vulnerability and Information Disclosure Vulnerability in post-edit.php

Open onEpAth936 opened this issue 3 years ago • 0 comments

environment:

  • php.7.3.4
  • win10

First,you need to Login the backstage here: /mc-admin/

image

Second,use payload: /mc-admin/post-edit.php?id=%3Cscript%3Ealert%285%29%3C/script%3E

image

you will see Pop-ups,then click here :

image

you will see Web Directory leak out like this:

image

onEpAth936 avatar Jul 09 '22 03:07 onEpAth936