Loading
0

DedeCMS v5.7 shops delivery 存储型XSS漏洞/en

免费、自由、人人可编辑的漏洞库--PwnWiki.com

,

Prerequisites

The site needs to enable the store function.

Exploit

Add in the background

Add delivery.png

After successful addition, the list of delivery methods will be displayed directly, and XSS will be triggered;
In addition, this XSS will also be triggered when the front-end user purchases something and chooses the delivery method

PWNWIK.COM