Stored XSS in the banner block description

Disclosed: 2021-03-09 10:11:48 By solov9ev To stripo
Medium
Vulnerability Details
## Steps To Reproduce: - Create a new template and add a banner block {F1128944} - Add a description to the banner block description: `"><img src=1 onerror=alert(document.domain)>` - Malicious code executed {F1128945} ## Proof Of Concept: {F1128942} ## Impact With this vulnerability, an attacker can for example steal users cookies or redirect users on malicious website.
Actions
View on HackerOne
Report Stats
  • Report ID: 1065964
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report