Cross-site Scripting (XSS) - Stored in bigprof-software/online-invoicing-system

Valid

Reported on

Jun 30th 2021


✍️ Description

There is a Stored XSS in the online invoicing system when adding a group name.

🕵️‍♂️ Proof of Concept

Video POC:
https://drive.google.com/file/d/13VaUfJrhd7m565lMQWZMfzXhfY_PVjPV/view?usp=sharing
Payload:
'''><svg/onload=prompt(5)>

💥 Impact

Stored XSS

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back a year ago
BigProf Software validated this vulnerability a year ago
x3rz has been awarded the disclosure bounty
The fix bounty is now up for grabs
BigProf
a year ago

I'd set the severity of this issue to low rather than medium. An administrator has no motive to XSS himself. So, this needs to be combined with a CSRF attack in order to be effective.

BigProf Software marked this as fixed with commit 2a29c6 a year ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation