Cross-site Scripting (XSS) - Stored in chaskiq/chaskiq

Valid

Reported on

Jan 14th 2022


Description

When building an app, an XSS vulnerability occurs in the app's name.

Proof of Concept

1. Go to App Settings
2. Enter "><img src=x onerror=alert(document.domain)> as the name of the app

Video : https://www.youtube.com/watch?v=dEFDHHGxzoY

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the chaskiq team within 24 hours. 4 months ago
Pocas modified the report
4 months ago
Pocas modified the report
4 months ago
Miguel Michelson Martinez validated this vulnerability 4 months ago
Pocas has been awarded the disclosure bounty
The fix bounty is now up for grabs
Miguel Michelson Martinez confirmed that a fix has been merged on bffa58 4 months ago
Miguel Michelson Martinez has been awarded the fix bounty
Dashboard.tsx#L122L129 has been validated
Miguel
4 months ago

Maintainer


Hey @admin, Can you assign a CVE?

Jamie Slome
4 months ago

Admin


CVE assigned and published! 🎊

to join this conversation