Cross-site Scripting (XSS) - Stored in bigprof-software/online-invoicing-system


Reported on

Jul 4th 2021

✍️ Description

stored xss via Group name

🕵️‍♂️ Proof of Concept

Step To Reproduce:

Go to /admin/pageEditGroup.php and creat a group with payload: '/><IMG SRC=# onerror="alert('xxs')">

Now visit user dashboard ie, /membership_profile.php and see the xss pops up

Poc video:

Note: On the video I logged in as admin on chrome and as a user in firefox to demonstrate!!

💥 Impact

Stored Xss

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back 2 years ago
BigProf Software marked this as fixed with commit 3edc6c 2 years ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation