Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm


Reported on

Dec 13th 2021


I found file upload XSS, Stored Cross-Site Scripting (XSS) vulnerability due to the lack of content validation and output encoding.

Proof of Concept

1. login and navigate to
2. Layout > photo > Add file.
3. Upload the XSS file upload payload.

File upload xss payload



Stored XSS generally occurs when user input is stored on the target server, such as in a database, in a message forum, visitor log, comment field, etc. And then a victim is able to retrieve the stored data from the web application without that data being made safe to render in the browser.

We are processing your report and will contact the yetiforcecompany/yetiforcecrm team within 24 hours. 2 years ago
A GitHub Issue asking the maintainers to create a exists 2 years ago
2 years ago


I am unable to induce vulnerability, please contact

2 years ago


Please download and upload this payload

Mariusz Krzaczkowski validated this vulnerability 2 years ago
Raptor has been awarded the disclosure bounty
The fix bounty is now up for grabs
Mariusz Krzaczkowski marked this as fixed in 6.4.0 with commit 9cdb01 2 years ago
Mariusz Krzaczkowski has been awarded the fix bounty
This vulnerability will not receive a CVE
File.php#L139-L251 has been validated
2 years ago


Bug fixed in 6.3.0_SecurityFix

to join this conversation