vulnerability cross-site scripting (xss) - stored (cwe-79)
severity 7.6
language php
registry other

✍️ Description

Stored xss via contact information

🕵️‍♂️ Proof of Concept

  1. First goto your account in and add a contact . Now add twitter type contact-information in this contact while put bellow payload in url and save it . Now whenever click this link then xss is executed


#Video POC --->

💥 Impact

Stored xss