Stored XSS in Supplier Company Description in inventree/inventree
Valid
Reported on
Jun 13th 2022
Description
The application inventree
is vulnerable to Stored XSS in supplier company description field.
Proof of Concept
Video PoC Link: https://drive.google.com/file/d/115LLo4rxW7RzWd7hevbSFAlf-V83OUhU/view?usp=sharing
Impact
This allows the attacker to execute malicious scripts in all the project members browser and it can lead to session hijacking, sensitive data exposure, and worse.
We are processing your report and will contact the
inventree
team within 24 hours.
a year ago
We have contacted a member of the
inventree
team and are waiting to hear back
a year ago
The researcher's credibility has increased: +7
to join this conversation