Bypass Stored XSS while creating a new post in usememos/memos
Valid
Reported on
Dec 30th 2022
Description
After login to portal create a new post and type the following text with XSS payload
Proof of Concept
Login to portal.
create a post with xss paylaod
save it
POC: https://drive.google.com/file/d/1WkQpGyQGKBS-9To5mlud_qkkL7VOp9Au/view?usp=share_link
Bypass Payload
/*/**<input type="text" value=`` <div/onmouseover='alert(1)'>X</div>**/*/*
Impact
Users & admin account takeover
We are processing your report and will contact the
usememos/memos
team within 24 hours.
10 days ago
Anil Bhatt modified the report
10 days ago
The researcher's credibility has increased: +7
to join this conversation