CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12002] Self-XSS vulnerability via Design Manager on CMSMS 2.2.10

avatar
Created By: Chi Tran (chitran)
Date Submitted: Sun Mar 24 23:41:02 -0400 2019

Assigned To:
Version: 2.2.10
CMSMS Version: 2.2.10
Severity: Trivial
Resolution: None
State: Open
Summary:
Self-XSS vulnerability via Design Manager on CMSMS 2.2.10
Detailed Description:
Hello CMSMS Team,

I am reaching out to report a Self XSS vulnerability via Design Manager feature
from CMS Made Simple version 2.2.10. An attacker can create a new template and
add payload into "Name" field.
Steps to reproduce:
- Navigate to Admin Dashboard
- Click on Layout -> Design Manager feature
- Click on "Create a new Template"
- In "Name" field, input payload: <svg/onload=alert(document.domain)>
- Click "Submit"
- After submitting, malicious script will be executed.




History