Skip to content
This repository has been archived by the owner on Oct 30, 2019. It is now read-only.

JavaScript Injection leak. #7

Open
SimonNitzsche opened this issue Nov 23, 2016 · 1 comment
Open

JavaScript Injection leak. #7

SimonNitzsche opened this issue Nov 23, 2016 · 1 comment

Comments

@SimonNitzsche
Copy link

You can add HTML (including JavaScript and CSS) and PHP in Forum-Posts.

That means, the user does have:

  • Full MySQL Access
  • Full File Access
  • Can hook Users
  • Can do other weird shit.
@ghost
Copy link

ghost commented Nov 25, 2016 via email

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant