Cross-site Scripting (XSS) - Generic in projectsend/projectsend


Reported on

Jan 10th 2022


Proof of Concept

Go to below url.XSS will be popuped.



We can takeover user account by fetching session cookie.Lower level user can make xss attack against admin. So, using this xss bug lower level user can execute arbitary javascript in admin account

We are processing your report and will contact the projectsend team within 24 hours. 5 months ago
We have contacted a member of the projectsend team and are waiting to hear back 5 months ago
Bikram kharal modified the report
5 months ago
Bikram kharal
4 months ago


Hey there, Any updates on this?

We have sent a follow up to the projectsend team. We will try again in 7 days. 4 months ago
Ignacio Nelson validated this vulnerability 4 months ago
Bikram kharal has been awarded the disclosure bounty
The fix bounty is now up for grabs
Ignacio Nelson confirmed that a fix has been merged on 3cf659 4 months ago
Ignacio Nelson has been awarded the fix bounty
