Cross-site Scripting (XSS) - Stored in zoujingli/thinkadmin
Valid
Reported on
Sep 15th 2021
Description
Stored xss
Proof of Concept
Plz check this 1 minute video to reproduce the bug https://drive.google.com/file/d/1hyN4X9gIgQJH2B5QEFhkniGt78sIw1iF/view?usp=sharing
Impact
Xss allow to arbitary javascript code execution
We have contacted a member of the
zoujingli/thinkadmin
team and are waiting to hear back
2 years ago
https://github.com/zoujingli/ThinkAdmin/blob/v6/public/static/plugs/ckeditor/config.js#L17
to join this conversation