Summary

An unchecked title parameter in 07FlyCRM (https://gitee.com/07fly/FLY-CRM/) system extension module allows authenticated users to perform XSS.

Impact

07FlyCRM≤1.2.9

Details&PoC

  1. When an authenticated user sets title as XSS payload "><img src=1 onerror=alert(1)>, which perform XSS

    image.png

    image.png

    image.png