MiniCMS
MiniCMS copied to clipboard
A Reflected Cross-Site Scripting vulnerability exists in the /mc-admin/page.php in version 1.11
vulnerability location:date parameter
/MiniCMS-1.11/mc-admin/page.php?state=draft&date=2024-04
Payload:
Access the address with payload after login:
/MiniCMS-1.11/mc-admin/page.php?state=draft&date=2024-04
Then we can find it triggering the xss vulnerability: