mao10cms 6 allows XSS via the m=bbs&a=index page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/nsmaomao/mao10cms/issues/2 | third party advisory |
https://github.com/chenrui1896/mao10cms_xss/wiki/The-xss-vulnerability-of-mao10cms | third party advisory |