Skip to content

Found xss vulnerability and Information Disclosure Vulnerability in post-edit.php #46

@onEpAth936

Description

@onEpAth936

environment:

  • php.7.3.4
  • win10

First,you need to Login the backstage here: /mc-admin/

image

Second,use payload: /mc-admin/post-edit.php?id=%3Cscript%3Ealert%285%29%3C/script%3E

image

you will see Pop-ups,then click here :

image

you will see Web Directory leak out like this:

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions