Cross-site Scripting (XSS) - Stored in chaskiq/chaskiq
Valid
Reported on
Jan 14th 2022
Description
When building an app, an XSS vulnerability occurs in the app's name.
Proof of Concept
1. Go to App Settings
2. Enter "><img src=x onerror=alert(document.domain)> as the name of the app
Video : https://www.youtube.com/watch?v=dEFDHHGxzoY
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.
Occurrences
We are processing your report and will contact the
chaskiq
team within 24 hours.
a year ago
Pocas modified the report
a year ago
Pocas modified the report
a year ago
Dashboard.tsx#L122L129
has been validated
to join this conversation