Cross-site Scripting (XSS) - Stored in chaskiq/chaskiq

Valid

Reported on

Jan 12th 2022


Description

chaskid is a Open Source Messaging Platform for Marketing, Support & Sales this package is vulnerable for xss

Proof of Concept

Imgur

Impact

This vulnerability is capable of stored XSS

We are processing your report and will contact the chaskiq team within 24 hours. a year ago
We created a GitHub Issue asking the maintainers to create a SECURITY.md a year ago
Miguel
a year ago

Maintainer


Hello, not sure how to reproduce the security issue, can you guide us?

Abdul muhaimin
a year ago

Researcher


Hey , really sorry for that , my link got broken or something happened with Imgur

Here is the gdrive for poc : https://drive.google.com/file/d/1bzuZZowCtn4yF5JoQwpJNQp1RzAFk6jL/view?usp=drivesdk

Thank you

Miguel
a year ago

Maintainer


Thanks, Abdul, I will take care of this issue asap!

Abdul muhaimin modified the report
a year ago
Miguel
a year ago

Maintainer


how can we help you back?

Miguel Michelson Martinez validated this vulnerability a year ago
Abdul muhaimin has been awarded the disclosure bounty
The fix bounty is now up for grabs
Abdul muhaimin
a year ago

Researcher


Thank you <3

Miguel Michelson Martinez marked this as fixed in 0.9.8 with commit 51768b a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
Miguel
a year ago

Maintainer


Hey @admin, Can you assign a CVE?

Jamie Slome
a year ago

Admin


CVE assigned and published! 🎊

to join this conversation