Skip to content

autumn-cms add user has XSS vulnerabilities #89

@niuzhi

Description

@niuzhi

Location:cms后台登陆,系统设置->用户管理->添加用户->登录名

image

POC:登录名:<script>alert("hack123")</script>
image

后台代码未进行输入过滤:
@RequestMapping(value = "insert/")
@responsebody
public ResponseMsg insertUser(User user){

    user.setPassword(MD5Util.getMD5(user.getPassword()));
    return userService.insertUser(user);
}

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions