Cross-site Scripting (XSS) - Stored in slackero/phpwcms


Reported on

Aug 19th 2021

✍️ Description

Stored xss

🕵️‍♂️ Proof of Concept

Plz check this 1 minute video

💥 Impact

xss bug


We have contacted a member of the slackero/phpwcms team and are waiting to hear back a year ago
Oliver Georgi validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Oliver Georgi confirmed that a fix has been merged on b39db9 a year ago
Oliver Georgi has been awarded the fix bounty
to join this conversation