Cross-site Scripting (XSS) - Stored in liangliangyy/djangoblog
Reported on
Jan 30th 2022
Description
Hi there, I would like to report a stored Cross Site Scripting vulnerability in djangoblog source code. Cross-site scripting (also known as XSS) is a web security vulnerability that allows an attacker to compromise the interactions that users have with a vulnerable application. It allows an attacker to circumvent the same origin policy, which is designed to segregate different websites from each other. Cross-site scripting vulnerabilities normally allow an attacker to masquerade as a victim user, to carry out any actions that the user is able to perform, and to access any of the user's data. If the victim user has privileged access within the application, then the attacker might be able to gain full control over all of the application's functionality and data
Proof of Concept
- Install a local instace of djangoblog
- Log in as admin and create an article with content
<img src=a onerror=alert(document.cookie)>
- Go to article detail page and see that a pop up appears with your cookie in it.
- A POC image
https://drive.google.com/file/d/11kWL4mWQNbABUtngJIBflF-dAbmMxZAy/view?usp=sharing
Impact
This vulnerability is capable of stored XSS.
Occurrences
article_info.html L54
Unsanitized blog body