Description
- It was found that the application suffers from stored XSS
- The vulnerability was found to be in the "Edit Profile" page
- Vulnerable parameter was "Content"
Stored XSS in "Edit Profile"
Steps to Reproduce:
- Login as author
- Browse to "Edit Profile"
- In "Content" field add payload "><img src=x onerror=alert(1)>
- Then refresh the "Edit Profile" page
No comments:
Post a Comment