Lucene search

K
huntrVautia0BBB1046-EA9E-4CB9-BC91-B294A72D1902
HistoryAug 28, 2022 - 4:44 p.m.

Stored Cross-Site Scripting (XSS)

2022-08-2816:44:56
vautia
www.huntr.dev
14
cross-site scripting
markdown input
superadmin permissions
proof of concept
bug bounty

0.001 Low

EPSS

Percentile

21.4%

Description

Input fields allowing Markdown Input are vulnerable to XSS. This requires Superadmin permissions though.

Proof of Concept

Steps to reproduce:

1. Log in to the admin account
2. Go to Admin -> General Settings
3. Enter the Payload in the `Login Note` and `Dashboard Message` fields.
4. Go to the Dashboard & confirm the XSS in the dasboard message. Logout and confirm the XSS in the login message.

Payload:

[XSS](javascript:alert(document.location))

0.001 Low

EPSS

Percentile

21.4%

Related for 0BBB1046-EA9E-4CB9-BC91-B294A72D1902