### [CVE-2019-13341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13341) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. ### POC #### Reference - https://github.com/bg5sbk/MiniCMS/issues/32 - https://github.com/bg5sbk/MiniCMS/issues/32 #### Github No PoCs found on GitHub currently.