Cross-site Scripting (XSS) - Stored in zikula/core
Reported on
Nov 29th 2021
Description
In zikula/core cross site scripting vulnerability is present in block module title field
Proof of Concept
login to the demo account
go to blocks https://demo.ziku.la/blocks/admin/view
Add payload in title field and save
4 payload = "><iMg SrC="x" oNeRRor="alert(1);">
Impact
This vulnerability is capable of stolen the user session