Cross-site Scripting (XSS) - Stored in bigprof-software/online-invoicing-systemValid
There is a Stored XSS on the user profile edit page which occurs due to improper sanitization of the Address field as tested on the latest release.
🕵️♂️ Proof of Concept
Step to reproduce: Go to /admin/pageSettings.php?search-settings=smtp and the payload: "<svg/onload=prompt(document.domain)>"@x.y in the "Senders Email" column Click Save; and visit /admin/pageMail.php?sendToAll=1 to see the pop-up, see the video
Poc video: https://drive.google.com/file/d/1UjuPoUlpkDt5uIDhjx5C6R9quH2U6FWp/view?usp=sharing