taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/ae6e361b/taocms-XSS | product third party advisory exploit |
https://gist.github.com/ae6e361b/b7f162eba1a91df3ad9dc71ec9935960 | third party advisory exploit |