fluentcms / fluentcms/FluentCMS

Reflected XSS vulnerability in FluentCMS

Open
#2,403 1 comment 3 reactions 2 assignees Claimed by @pournasserian View on GitHub
bug
Dominant language
C#
Stars
565
Forks
107
PR merge metrics
No merged PRs in 30d

Description

Description:
A reflected cross-site scripting (XSS) vulnerability was identified in the admin page.
User input is not properly sanitized before being reflected in the HTTP response.

Impact:
An attacker could craft a malicious URL that executes arbitrary JavaScript in the victim’s browser.

Recommendation:
Implement proper input validation and output encoding on both frontend and backend.

Note:
Detailed reproduction steps and screenshots have been shared with the maintainer privately.

You can reproduce the vulnerability by following the steps below.

Image

Image

Image

Image

Image

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.