Stored XSS through Facebook Page Connection
Low
S
Shopify
Submitted None
Actions:
Reported by
boredengineer21
Vulnerability Details
Technical details and impact analysis
The following URL
https://kitcrm.com/users/122686/connections
displays us options to connect our several social networking accounts to kitcrm.
Once i connect my facebook account, the facebook section in above link will list out all my facebook page and will give me an option to select a business page.
One of my facebook page name is "><img src=x onerror=alert(9)>
F220032: Screenshot from 2017-09-11 22-23-23.png 54.6KB
Now when i click on that drop-down option an alert will pop-up.
F220033: Screenshot from 2017-09-11 22-25-20.png
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored