Loading HuntDB...

Stored XSS through Facebook Page Connection

Low
S
Shopify
Submitted None
Reported by boredengineer21

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
The following URL https://kitcrm.com/users/122686/connections displays us options to connect our several social networking accounts to kitcrm. Once i connect my facebook account, the facebook section in above link will list out all my facebook page and will give me an option to select a business page. One of my facebook page name is "><img src=x onerror=alert(9)> F220032: Screenshot from 2017-09-11 22-23-23.png 54.6KB Now when i click on that drop-down option an alert will pop-up. F220033: Screenshot from 2017-09-11 22-25-20.png

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored