Lucene search

K
huntrRajbabai8F6082949-40D3-411C-B613-23ADA2691913
HistoryJun 03, 2022 - 6:32 p.m.

Account takeover due to stored XSS in "Project Title"

2022-06-0318:32:19
rajbabai8
www.huntr.dev
21
nocodb
stored xss
admin account

EPSS

0.001

Percentile

21.4%

Description

The Project “Title” of the NocoDB application is vulnerable to stored xss which can leads to admin account takeover.

Proof of Concept

Login with low privileged users and Click on "New Project" then click on "Create"

Now write the payload <img src> and again click on "Create"

Then login from super admin account and "delete" the created project  <img src>

poc video

https://drive.google.com/file/d/1tVJFpajTWGOrgYvLj2eHfqcrLcWCSKnG/view?usp=sharing

EPSS

0.001

Percentile

21.4%

Related for F6082949-40D3-411C-B613-23ADA2691913