Lucene search

K
huntrMnqazi705F79F4-F5E3-41D7-82A5-F00441CD984B
HistoryMay 07, 2023 - 12:40 p.m.

Stored HTML Injection in Item Label

2023-05-0712:40:59
mnqazi
www.huntr.dev
13
html injection
item label
folder access
malicious users
redirection
data capture
bug bounty

EPSS

0.001

Percentile

23.5%

Description

If two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker’s website or capture their data using a form.

Proof of Concept

https://drive.google.com/file/d/1UkeRtAAIhwYTxvVCSrIozCUDukhrlVBT/view

EPSS

0.001

Percentile

23.5%

Related for 705F79F4-F5E3-41D7-82A5-F00441CD984B