Lucene search

K
huntrDev6961D124520-CF29-4539-A0F3-6D041AF7B5A8
HistoryDec 10, 2021 - 6:38 p.m.

Cross-site Scripting (XSS) - Reflected in yetiforcecompany/yetiforcecrm

2021-12-1018:38:43
dev696
www.huntr.dev
8

0.001 Low

EPSS

Percentile

30.1%

Description

Application is vulnerable to Reflected cross site scripting attack on create Invoice.

Proof of Concept

Step 1: Login into the application https://gitstable.yetiforce.com/index.php

Step 2: Navigate to Quick Create -> Cost Invoice

Step 3: Click on Source and enter the XSS Playload in Description and observe the pop up.

Video POC

https://1drv.ms/v/s!Aqx9_ZDlUWrJcGCc3xjV-n28ntE?e=FvuKQR

0.001 Low

EPSS

Percentile

30.1%

Related for 1D124520-CF29-4539-A0F3-6D041AF7B5A8