Stored Xss in neorazorx/facturascripts
Reported on
May 9th 2022
Description
Hi i found stored xss due to website field
Proof of Concept
- Create a new non-admin account
- Login and goto http://localhost/invoices/EditAgenciaTransporte add new user with website link to "javascript:confirm(document.domain)"
- Save user and navigate to http://localhost/invoices/ and click on the website link of newly created user
Impact
Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser