Lucene search

K
huntrAravindd0074746F149-FC55-48A1-A7AB-FD7C7412C05A
HistoryApr 11, 2022 - 5:35 p.m.

Cross-site Scripting (XSS) - Stored

2022-04-1117:35:11
aravindd007
www.huntr.dev
11

0.001 Low

EPSS

Percentile

21.6%

Description

Stored Cross-Site Scripting (XSS) vulnerability due to the lack of content validation and output encoding. This vulnerability can be exploited by uploading a crafted payload inside a document. Then, the vulnerability can be triggered when the user previews the documentΒ΄s content.

Proof of Concept

https://drive.google.com/file/d/1xJh3wjyBUB5JF0rsbPblrUUREvtHA-EG/view?usp=sharing

0.001 Low

EPSS

Percentile

21.6%

Related for 4746F149-FC55-48A1-A7AB-FD7C7412C05A