Cross-site Scripting (XSS) - Stored in slackero/phpwcms

Valid

Reported on

Aug 19th 2021


✍️ Description

Stored xss

🕵️‍♂️ Proof of Concept

Plz check this 1 minute video https://drive.google.com/file/d/1ycKDrN3ot623c-iYTaJYFNCjxCXChNx1/view?usp=sharing

💥 Impact

xss bug

Occurrences

We have contacted a member of the slackero/phpwcms team and are waiting to hear back 2 years ago
Oliver Georgi validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Oliver Georgi marked this as fixed with commit b39db9 2 years ago
Oliver Georgi has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation