Cross-site Scripting (XSS) - Stored in bigprof-software/online-invoicing-system

Valid

Reported on

Jul 1st 2021


💥 BUG

Stored xss via client address in invoice

💥 TESTED VERSION

latest version as of 01/07/21

💥 STEP TO REPRODUCE

1. From admin account goto http://localhost/online-invoice2/app/admin/pageViewMembers.php and add a new user called user-B with read-write permission in invoice/client module .
2. Now goto user-B account and created a client and during creation put bellow xss payload in address field .
xss"'><img src=x onerror=alert(document.domain)> .
3. Now goto admin account and create a invoice and during creation select above created client in client field and see xss is eexecuted

💥 VIDEO POC

https://drive.google.com/file/d/1YmouqeK5orMQYuEJCo-YPs4FNeqba5oz/view?usp=sharing

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back a year ago
BigProf Software validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
BigProf Software marked this as fixed with commit 561c0f a year ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation