We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Location:cms后台登陆,系统设置->用户管理->添加用户->登录名
POC:登录名:<script>alert("hack123")</script>
后台代码未进行输入过滤: @RequestMapping(value = "insert/") @responsebody public ResponseMsg insertUser(User user){
user.setPassword(MD5Util.getMD5(user.getPassword())); return userService.insertUser(user); }
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Location:cms后台登陆,系统设置->用户管理->添加用户->登录名
POC:登录名:<script>alert("hack123")</script>
后台代码未进行输入过滤:
@RequestMapping(value = "insert/")
@responsebody
public ResponseMsg insertUser(User user){
The text was updated successfully, but these errors were encountered: