I have found Reflected Cross-Site Scripting on WolfCMS (0.8.3.1) Stable Version
Vulnerable parameter is "Create New File" and "Create New Directory"
It does not sanitize "Create New File" and "Create New Directory" input box from 'files' Tab and it is possible to execute a Cross-Site Scripting XSS attacks.
Payload Used : <script>alert(0);</script>

Please find the attached screenshot for proof of concept.


Additional information

  • Wolf CMS version: 0.8.3.1
  • DB type and version: MySQL - 10.1.9-MariaDB
  • HTTP server type and version: PHP/5.6.15
When you fix the bug, please, can you include my name in the release notes when the bug will be corrected? 
Name : Tushar  Kadam


Comments

Popular posts from this blog

CSRF on Change Password