After the administrator logged in,open the poc page.
copy add.txt to add.html and let the administrator open the add.html
vulnerability location:/EmpireCMS-master/upload/e/admin/user/AddUser.php?enews=AddUser
Before modification


After modification

Payload location:
add.txt
After the administrator logged in,open the poc page.
copy add.txt to add.html and let the administrator open the add.html
vulnerability location:/EmpireCMS-master/upload/e/admin/user/AddUser.php?enews=AddUser
Before modification
After modification

Payload location:
add.txt