View Issue Details

IDProjectCategoryView StatusLast Update
4668Composrcore_feedback_featuresprivate2021-08-16 02:48
ReporterGuest Assigned ToChris Graham  
PrioritynormalSeveritySecurity-hole 
Status resolvedResolutionfixed 
Summary4668: stored XSS
DescriptionHello! I found stored xss from guest to admin via feedback. Version 10.0.37.

PoC video (pwd: str0ngp@ssw0rd)
https://dropmefiles.com/4llfn
​​​​​​​
Can you register cve? it's just to increase self-esteem :)
Thanks.
Steps To Reproduceclick to feedback link.
put <img/src/onerror=alert('XSS')> into "Subject" field

log in as admin
go to /adminzone/index.php?page=admin-messaging and click to new message
TagsNo tags attached.
Attach Tags
Time estimation (hours)
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

Chris Graham

2021-08-15 02:20

administrator   ~7114

Thank you for your report. I'm looking into this.

Chris Graham

2021-08-16 02:48

administrator   ~7119

This (actually 2 bugs) has been publicly resolved and covered in https://compo.sr/news/view/announcements/two-new-xss-security.htm

Issue History

Date Modified Username Field Change
2021-08-10 11:12 Guest New Issue
2021-08-15 02:20 Chris Graham Note Added: 0007114
2021-08-15 19:07 Chris Graham Assigned To => Chris Graham
2021-08-15 19:07 Chris Graham Status Not Assigned => Resolved
2021-08-15 19:07 Chris Graham Resolution open => fixed
2021-08-16 02:48 Chris Graham Note Added: 0007119