Loading HuntDB...

Stored XSS triggered by json key during UI generation

A
Algolia
Submitted None
Reported by ctee

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Stored XSS is triggred from **Indices** -> **Generate a UI Demo**. Typing anything in the **Primary, Secondary, Tertiary, Image or URL attributes** for **User Interface** section. These text box have a drop down which displays the json keys during which XSS is triggered. Sample json for XSS would be ``{ "<img src=1 onerror=alert(document.domain)>": "hello", }`` Attached: screen shot

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic