2022-02-20 16:14:31 +08:00
|
|
|
|
# 极致CMS 1.81 后台存储型XSS
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞描述
|
|
|
|
|
|
|
|
|
|
|
|
极致CMS后台中存在存储XSS,通过XSS漏洞,可能泄漏敏感信息
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞影响
|
|
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
|
极致CMS
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## FOFA
|
|
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
|
icon_hash="1657387632"
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞复现
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|
网站主页
|
2022-02-20 16:14:31 +08:00
|
|
|
|
|
|
|
|
|
|
登录管理员添加模块
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-02-20 16:14:31 +08:00
|
|
|
|
|
|
|
|
|
|
注册用户
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-02-20 16:14:31 +08:00
|
|
|
|
|
|
|
|
|
|
点击发布文章
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-02-20 16:14:31 +08:00
|
|
|
|
|
|
|
|
|
|
在文章标题处插入xss payload
|
|
|
|
|
|
|
|
|
|
|
|
- `<details open ontoggle= confirm(document[`coo`+`kie`])>`
|
|
|
|
|
|
|
|
|
|
|
|
当管理员访问时XSS成功
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-02-20 16:14:31 +08:00
|
|
|
|
|