• 本文作者: 阿尔法实验室漏洞报送
  • |
  • 2019年6月3日
  • |
  • CVE
  • |

Typesetter 5.1 Storage type Cross-Site Scripting

#site: http://www.typesettercms.com

#Version: 5.1

#Introduction

Typesetter is free, open source CMS which is faster and Easier.  There is a storage XSS vulnerability in position Settings-> Manage Classes

 

#Proof of Concepts:

1 – visit: http://127.0.0.1/Typesetter/index.php/Admin/Classes

2 – In the “className” and “Description” field , input test”><script>alert(1)</script>

3 – click the Save button

4 – visit http://127.0.0.1/Typesetter/index.php/Admin/Classes ,  XSS box will then pop-up

Written by 阿尔法实验室漏洞报送