# Affected software: demo.radiantcms.org # Discovered by: Provensec # Website: http://www.provensec.com # Author:Ankit Bharathan,Provensec Labs # Type of vulnerability: XSS Stored # Description: 1 Goto http://demo.radiantcms.org/admin/layouts 2 Add new layout with name as xss payload <svg><script>alert(/1/)< /script> 3 Save it Screenshot - http://prntscr.com/4jk6nv