Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

There is a stored XSS vulnerability #112

Open
N0boy-0 opened this issue May 7, 2024 · 1 comment
Open

There is a stored XSS vulnerability #112

N0boy-0 opened this issue May 7, 2024 · 1 comment

Comments

@N0boy-0
Copy link

N0boy-0 commented May 7, 2024

First request to add a questionnaire and enter the xss payload in the title of the questionnaire.

man1

The DWSurvey system does not filter user input when processing requests.

code1

xss payload is inserted into the database.

code2
code3

The payload is not triggered at the title, but the surveyName is directly set to innerHtml in the popover.

eval
front

@easyandeasy
Copy link

easyandeasy commented May 7, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants