Loading HuntDB...

Stored XSS in the banner block description

Medium
S
Stripo Inc
Submitted None
Reported by solov9ev

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
## Steps To Reproduce: - Create a new template and add a banner block {F1128944} - Add a description to the banner block description: `"><img src=1 onerror=alert(document.domain)>` - Malicious code executed {F1128945} ## Proof Of Concept: {F1128942} ## Impact With this vulnerability, an attacker can for example steal users cookies or redirect users on malicious website.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored