Cross-site Scripting (XSS) - Stored in bigprof-software/online-invoicing-system


Reported on

Jul 2nd 2021

✍️ Description

There is a Stored XSS in the online invoicing system view price history which is lead by adding invoice items.


🕵️‍♂️ Proof of Concept

POC Video:

Steps to reproduce:
1. Click on Price History
2. Click on Add new.
3. Now you need to add new item named s"'><img src=x onerror=alert(document.domain)> and save it.
4. Now click on Invoice Items and then click on add.
5. In Invoice items:Add New you will see Item in which you will see the payload you added before select that and save it
6. You will see the Pop-up.

💥 Impact

Stored XSS, steal admin cookies if any user has access to add invoice items,add price history.

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back 2 years ago
BigProf Software validated this vulnerability 2 years ago
x3rz has been awarded the disclosure bounty
The fix bounty is now up for grabs
2 years ago


Thanks for researching this one. It's a really nasty issue.

BigProf Software marked this as fixed with commit d74504 2 years ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
2 years ago


thank you Sir can you please have a look on my other one that report1 report2

2 years ago


I replied to both reports. Please check my replies in each.

2 years ago


please check replies in each

