An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://kingflyme.blogspot.com/2018/11/the-poc-of-s-cmsxss.html | third party advisory exploit |