Cross-site Scripting (XSS) - Stored in namelessmc/nameless


Reported on

Aug 24th 2021

✍️ Description

stored xss via forum

🕵️‍♂️ Proof of Concept

1. First goto http://localhost/nameless/index.php?route=/panel/forums/&action=new and create a forum.
During creation put bellow xss paylaod in forum icon.\

xss"'><img src=x onerror=alert()>

2. Now save it .
3. Now goto above forum url http://localhost/nameless/index.php?route=/forum/view/2-forum/ and see xss is executed.

💥 Impact

xss allow to execute arbitary javascript code in victim account

We have contacted a member of the namelessmc/nameless team and are waiting to hear back a year ago
Sam validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Sam confirmed that a fix has been merged on 2c0151 a year ago
The fix bounty has been dropped
to join this conversation