Reflected Cross site scripting in neorazorx/facturascripts
Reported on
May 9th 2022
Description
When a user add new product with a supplier, supplier reference field is responsible to rxss
Proof of Concept
- Navigate to http://localhost/invoices/EditProducto?code=1&action=save-ok and goto supplier tab
- Click on Add and in "Supplier reference" field add hey '"><script>confirm(domain.cookie)</script>' payload
- Save and you will see a prompt
Impact
Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser