Skip to content

[BUG] Found Xss Stored vuln in Administration page #271

@GrayR0ot

Description

@GrayR0ot

Describe the bug | Décrivez le bug

Edit members from admin panel allow us using Xss Stored vulnerability

To Reproduce | Pour reproduire le bug

Steps to reproduce the behavior: | Étapes pour reproduire le bug :

  1. Go to Membres -> Edit any

  2. Set the user name to <script>alert("XSS");</script>

  3. Then save

It allow us using Stored Xss vulnerability. Which would allow us stoling visitors cookies and more other fun facts

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions