Cross-site Scripting (XSS) - Stored in namelessmc/nameless
Valid
Reported on
Aug 24th 2021
✍️ Description
stored xss via forum
🕵️♂️ Proof of Concept
1. First goto http://localhost/nameless/index.php?route=/panel/forums/&action=new
and create a forum.
During creation put bellow xss paylaod in forum icon
.\
xss"'><img src=x onerror=alert()>
2. Now save it .
3. Now goto above forum url http://localhost/nameless/index.php?route=/forum/view/2-forum/
and see xss is executed.
image1-->https://ibb.co/hs0zsQ7
image2-->https://ibb.co/Fnghdds
💥 Impact
xss allow to execute arbitary javascript code in victim account
Occurrences
We have contacted a member of the
namelessmc/nameless
team and are waiting to hear back
2 years ago
to join this conversation