Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reflecting xss vulnerability #82

Open
qingsanz opened this issue Feb 26, 2025 · 1 comment
Open

Reflecting xss vulnerability #82

qingsanz opened this issue Feb 26, 2025 · 1 comment

Comments

@qingsanz
Copy link

Cloud light forum system foreground reflection xss vulnerability

Feel free to register an account and click Insert file at the post

Image

Select a file and upload captured packets to change the name of the file

Image

Image

Image

@diyhi
Copy link
Owner

diyhi commented Mar 4, 2025

这个问题不会对系统用户安全产生影响,这个只是抓取数据包的用户修改自身上传文件的回显信息,只有抓包的用户自已上传时才会显示这种结果,不会影响其他用户,也不会形成影响安全的XSS漏洞。发贴提交到后端的内容都会进行XSS过滤,数据库不会存储包含XSS的代码。为消除这种显示问题,6.6版本会对上传的文件名回显进行转义。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants