Reflected Cross site scripting in neorazorx/facturascripts
Valid
Reported on
May 9th 2022
Description
When a user add new product with a supplier, supplier reference field is responsible to rxss
Proof of Concept
- Navigate to http://localhost/invoices/EditProducto?code=1&action=save-ok and goto supplier tab
- Click on Add and in "Supplier reference" field add hey '"><script>confirm(domain.cookie)</script>' payload
- Save and you will see a prompt
Impact
Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser
We are processing your report and will contact the
neorazorx/facturascripts
team within 24 hours.
a year ago
The researcher's credibility has increased: +7
to join this conversation