Hello,my nickname is isecream,I found a stored xss in the logo
First, access the page

the logo is obtained from database.

Then,i write the xss payload to the database via /publiccms/admin/sysSite/sql.html

you can see,the value has been changed

And then,access the last page

so,there is a stored xss in the all logo
Hello,my nickname is isecream,I found a stored xss in the logo
First, access the page

the logo is obtained from database.

Then,i write the xss payload to the database via /publiccms/admin/sysSite/sql.html

you can see,the value has been changed

And then,access the last page

so,there is a stored xss in the all logo