# ADD connectioins Title Storage XSS
`/ari-adminer/includes/controllers/connections/class-ajax-save.php line 9`
![](https://images.seebug.org/contribute/7c5468a2-0d1f-41c6-8f4a-b0cacf2e3acc-w331s)
GET the variable Connection
Follow the function save,`/air-adminer/includes/models/class-connection.php line 7`
![](https://images.seebug.org/contribute/cb7c1d49-617d-48f4-b426-8fec191388e8-w331s)
there are some general processing in the process, and only judge whether it is empty.No filtering for xss
![](https://images.seebug.org/contribute/7c03712e-dedb-4f61-9215-17db40744aef-w331s)
that data insert into database
![](https://images.seebug.org/contribute/a795b9ac-486e-488d-9fe9-c55ad79bd9c3-w331s)
## demo
payload in title
![](https://images.seebug.org/contribute/db823198-e0d9-4ac6-881f-7ca2100bb1f8-w331s)
![](https://images.seebug.org/contribute/ebbc8112-ad15-47e4-86cb-779fa9a9b6dc-w331s)
暂无评论