Stored XSS in memos while creating in usememos/memos
Valid
Reported on
Dec 23rd 2022
Description
After login create a new memo with the following XSS payload
"><img src=x onerror=alert(1)>#{
and click save that will make alert
Proof of Concept
"><img src=x onerror=alert(1)>#{
Impact
Account takeover via steal cookies
We are processing your report and will contact the
usememos/memos
team within 24 hours.
17 days ago
We have contacted a member of the
usememos/memos
team and are waiting to hear back
16 days ago
The researcher's credibility has increased: +7
to join this conversation