Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit


Reported on

Aug 15th 2023


Reflected Cross-Site Scripting (XSS) vulnerability allows attackers to execute arbitrary external javascript code in the browser. In the application there exists a XSS vulnerability that occurs in the api:

 Payload: "><script>alert(window.location)</script>

 GET /system/api/restApiViewer: Passing XSS payload to any param leads to XSS vulnerability.
 GET /system/api/graphqlViewer: Passing XSS payload to param `apiKey` leads to XSS vulnerability.

Proof of Concept


Through the hole. attacker can execute malicious code

Nguyen Hoan modified the report
6 months ago
