Skip to content

XSS in cmd.php for 1.2.5 #130

Closed
Closed
@4ndygu

Description

@4ndygu

A user can set a field to an XSS payload, which triggers when the confirmation screen for whether to confirm the change is raised.

From cmd.php, say I have an attribute set to the following:

Screen Shot 2020-12-01 at 9 55 48 AM

Then, say I am an admin and would like to change that field back:

Screen Shot 2020-12-01 at 9 56 09 AM

When the field prompts me for a change, the payload is triggered. A user can log into user 1 and request a change, then wait for an admin to try deleting the field, which would trigger the payload for that user.

Screen Shot 2020-12-01 at 9 56 16 AM

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions