A stored Cross-Site Scripting (XSS) vulnerability exists in the site name field. The application fails to sanitize input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field.
Required Permissions
- Administrator account
allowAdminChanges must be enabled.
Steps to Reproduce
- Log in to the CP as admin.
- Settings > Sites > create or rename a site. Set the Name to any XSS payload.
- Navigate to Settings > Email & Notice the XSS execution.
Impact
Stored XSS in the control panel.
Report ID: 1511
A stored Cross-Site Scripting (XSS) vulnerability exists in the site name field. The application fails to sanitize input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field.
Required Permissions
allowAdminChangesmust be enabled.Steps to Reproduce
Impact
Stored XSS in the control panel.
Report ID: 1511