Stored XSS in Name of Team Member Invitation
Low
L
Localize
Submitted None
Actions:
Reported by
abdulsec
Vulnerability Details
Technical details and impact analysis
hello team
i have found an stored in add team member
##Step to reproduce
1. Go to https://localizestaging.com/organization/team?filter=all
2. click on add team member
3. On the name, enter payload: </script><svg onload=alert(document.domain)>
4. and in the email add your victim email
4. when he join the team the xss will trigger.
{F701271}
now victim , can't logout, he can't do anything in his account
best regards
@moodiabdoul3
## Impact
the victim can nothing in his account
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate
Submitted
Weakness
Cross-site Scripting (XSS) - Stored