⚠ In case you've missed it, we have migrated to our new website, with a brand new forum. For more details about the migration you can read our blog post for website migration. This is an archived forum. ⚠

  •     

profile picture

image- crud XSS vulnerability 2 - images with titles



J-c
  • profile picture
  • Member

Posted 10 February 2013 - 23:39 PM

Hello,

 

I use Image-crud.

I filled the field "title" (example 4) with : <script>alert('lol');</script>

After the title is saved (f5), when i open the image i have a popup with the "lol" alert.

 

h2QuDsA.jpg

 

 

GAgQIx4.jpg