Cross-site Scripting (XSS) - Generic in projectsend/projectsend


Reported on

Jan 10th 2022


Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it.

Proof of Concept

Go to below url.XSS will be popuped.



We can takeover user account by fetching session cookie.Lower level user can make xss attack against admin. So, using this xss bug lower level user can execute arbitary javascript in admin account

We are processing your report and will contact the projectsend team within 24 hours. a year ago
We have contacted a member of the projectsend team and are waiting to hear back a year ago
Bikram kharal modified the report
a year ago
Bikram kharal
a year ago


Hey there, Any updates on this?

We have sent a follow up to the projectsend team. We will try again in 7 days. a year ago
Ignacio Nelson validated this vulnerability a year ago
Bikram kharal has been awarded the disclosure bounty
The fix bounty is now up for grabs
Ignacio Nelson marked this as fixed in r1340 with commit 3cf659 a year ago
Ignacio Nelson has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation