Stored XSS on Blog's page Tile

Disclosed: 2015-07-08 18:37:36 By ishahriyar To concretecms
Unknown
Vulnerability Details
In blog page Custom Title Text , xss payload can be executed and saved permanently . Poc: "><img src=x onerror=alert(1)>
Actions
View on HackerOne
Report Stats
  • Report ID: 50552
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report