Cross-site Scripting (XSS) - Stored in namelessmc/nameless

Valid

Reported on

Aug 24th 2021


✍️ Description

stored xss via forum

🕵️‍♂️ Proof of Concept

1. First goto http://localhost/nameless/index.php?route=/panel/forums/&action=new and create a forum.
During creation put bellow xss paylaod in forum icon.\

xss"'><img src=x onerror=alert()>

2. Now save it .
3. Now goto above forum url http://localhost/nameless/index.php?route=/forum/view/2-forum/ and see xss is executed.
image1-->https://ibb.co/hs0zsQ7
image2-->https://ibb.co/Fnghdds

💥 Impact

xss allow to execute arbitary javascript code in victim account

We have contacted a member of the namelessmc/nameless team and are waiting to hear back 2 years ago
Sam validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Sam marked this as fixed with commit 2c0151 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation