MinDoc has a stored XSS vulnerability due to not filtering the onfocus attribute.
Author: sky-teacherCreated Jul 30, 2025Updated Jul 30, 2025
1.Edit the article create an input box with the 'onfocus' attribute
- save and Publish
3.Anyone who visits this article and clicks on this input box will trigger XSS. (I used another browser without logging in to test)
Source: mindoc-org/mindoc