Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS Vulnerability v2.0.1 #83

Open
zxc7528064 opened this issue May 31, 2020 · 6 comments
Open

XSS Vulnerability v2.0.1 #83

zxc7528064 opened this issue May 31, 2020 · 6 comments

Comments

@zxc7528064
Copy link

zxc7528064 commented May 31, 2020

Affected software : livestreet CMS

Version : v.2.0.1

Type of vulnerability : XSS (Cross-Site Scripting)

Author : Noth

Description:
livestreet CMS is susceptible to cross-site scripting attacks, allowing malicious users to inject code into web pages, and other users will be affected when viewing web pages

Step 1 : login system
3

Step 2 : go to “/LiveStreet_2.0.1/admin/settings/config/main/” page

Step 3 : insert "XSS" test grammar in "Название сайта" and save it.
4

step 4 : Back to the front desk
6

@lifecom
Copy link

lifecom commented Jun 1, 2020

This page available only for site admin

@zxc7528064
Copy link
Author

zxc7528064 commented Jun 1, 2020

@lifecom Hi ~ Reply this Security issue to you, hope you can fix it . This is a Stored XSS !

@zxc7528064 zxc7528064 changed the title XSS Vulnerability XSS Vulnerability v2.0.1 Jun 2, 2020
@oleg-demidov
Copy link

Благодарю за помощь. Вы можете сделать вилку и работать с проектом как со своим

@zxc7528064
Copy link
Author

@olezhikz Thank you

@zxc7528064
Copy link
Author

@olezhikz Can I use this Security apply a CVE ID ?
https://cve.mitre.org/

Regards,

@zxc7528064
Copy link
Author

@olezhikz

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants