[CVE-2022–42094]Backdrop-XSS-at-Cards
Oct 31, 2022
Enter your username and password; the account must have admin privileges.
Press enter or click to view image in full size![]()
Select Content > add content > Card
Press enter or click to view image in full size![]()
Enter information into the form provided and enter the XSS payload in the Body field. Choose “Raw HTML” Editor and Save.
Press enter or click to view image in full size![]()
The XSS payload will run immediately.
Press enter or click to view image in full size![]()
POC:
Press enter or click to view image in full size![]()
