Awesome-POC/CMS漏洞/极致CMS 1.81 后台存储型XSS.md

43 lines
611 B
Markdown
Raw Normal View History

2022-02-20 16:14:31 +08:00
# 极致CMS 1.81 后台存储型XSS
## 漏洞描述
极致CMS后台中存在存储XSS通过XSS漏洞可能泄漏敏感信息
## 漏洞影响
```
极致CMS
```
## FOFA
```
icon_hash="1657387632"
```
## 漏洞复现
2022-12-05 11:09:28 +08:00
网站主页![img](./images/202202170914080.png)
2022-02-20 16:14:31 +08:00
登录管理员添加模块
2022-12-05 11:09:28 +08:00
![](./images/202202170915540.png)
2022-02-20 16:14:31 +08:00
注册用户
2022-12-05 11:09:28 +08:00
![](./images/202202170915958.png)
2022-02-20 16:14:31 +08:00
点击发布文章
2022-12-05 11:09:28 +08:00
![](./images/202202170915367.png)
2022-02-20 16:14:31 +08:00
在文章标题处插入xss payload
- `<details open ontoggle= confirm(document[`coo`+`kie`])>`
当管理员访问时XSS成功
2022-12-05 11:09:28 +08:00
![](./images/202202170915879.png)
2022-02-20 16:14:31 +08:00