Stored XSS in Part IPN in inventree/inventree
Jun 11th 2022
inventree is vulnerable to Stored XSS in part IPN field.
Proof of Concept
Video PoC link: https://drive.google.com/file/d/1HE_y7XS89FlzVSPFGilowBrBDMPAfC_s/view?usp=sharing
This allows the attacker to execute malicious scripts in all the project members browser and it can lead to session hijacking, sensitive data exposure, and worse.