CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12092] Stored Cross-site Scripting in Content Content Manager module

avatar
Created By: feioklucy (feioklucy)
Date Submitted: Tue Aug 06 02:33:44 -0400 2019

Assigned To:
Version: 2.2.10
CMSMS Version: 2.2.10
Severity: Minor
Resolution: Invalid
State: Closed
Summary:
Stored Cross-site Scripting in Content Content Manager module
Detailed Description:
Hello CMSMS Team,

I am reaching out to report a Stored XSS vulnerability via Content Manager
module feature from CMS Made Simple version 2.2.10. 
Steps to reproduce:
- Navigate to Admin Dashboard
- Click on Content -> Content Manager Module
- Click on "Add New Content"
- Click on "Logic"
- In "Page Specific Metadata" field, input payload: <img src=#
onerror="alert(1)">
- Click "Submit"
- After submitting, payload will be executed every time we click on  "View this
page in another window " .


History

Comments
avatar
Date: 2019-08-06 02:44
Posted By: feioklucy (feioklucy)

- Navigate to Admin Dashboard
- Click on Content -> Content Manager Module
      
Updates

Updated: 2020-11-03 14:37
state: Open => Closed

Updated: 2019-09-21 09:48
resolution_id: 5 => 9

Updated: 2019-08-06 02:44
description: Hello CMSMS Team, I am reaching out to report a Stored XSS vulnerability via Content Manager module feature from CMS Made Simple version 2.2.10. Steps to reproduce: - Navigate to Admin Dashboard - Click on Content -> Content Manager - News Module => Hello CMSMS Team, I am reaching out to report a Stored XSS vulnerability via Content Manager module feature from CMS Made Simple version 2.2.10. Steps to reproduce: - Navigate to Admin Dashboard - Click on Content -> Content Manager Module - Clic
resolution_id: => 5