The HiChat
application is a simple chat
for small teams
which is based on a small server
which helps to track
messages sent by various users.
The project presents a stored XSS
issue which could lead to session stealing
or HTML/JS injection
in a permanent way, until the victim leaves the chat room
.
npm i
node server
chat room
and set your username as test"><img/src="x"/onerror="alert(document.domain)">
chat room
of the attacker
)attacker
sends any message, the username
is insecurely reflected and JS injected