Affected Versions:
Disczu! <= 7.2
Discuz! Vulnerability description for All Versions:
Discuz! The "personal signature" in the personal center does not detect malicious code. In Discuz! When the img code is disabled, malicious code can still be written, Discuz! The code is saved and executed to form a permanent cross-site.
This vulnerability may cause the spread of worms. <* Reference
Liscker@hotmail.com
*>
Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! </Textarea> <script> alert (/Liscker/); </script> <textarea> SEBUG Security suggestions:
No official patch is available. Please wait for updates from the official website administrator.
Temporary solution:
1. Modify the memcp. php code to filter personal signature characters.
2. Prohibit users from using personal signatures.