Loading HuntDB...

Stored XSS in Name of Team Member Invitation

Low
L
Localize
Submitted None
Reported by abdulsec

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
hello team i have found an stored in add team member ##Step to reproduce 1. Go to https://localizestaging.com/organization/team?filter=all 2. click on add team member 3. On the name, enter payload: </script><svg onload=alert(document.domain)> 4. and in the email add your victim email 4. when he join the team the xss will trigger. {F701271} now victim , can't logout, he can't do anything in his account best regards @moodiabdoul3 ## Impact the victim can nothing in his account

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Cross-site Scripting (XSS) - Stored