Store XSS when Add Reviewer in pkp/pkp-lib
Reported on
Oct 12th 2023
Description
Store XSS when Add Reviewer
Proof of Concept
Payload:
TEST<script>alert(document.domain)</script>
Video Poc
https://drive.google.com/file/d/16o4w6V-uCpkshFXYBb-pZRflpl7N3Sy4/view?usp=sharing
Impact
This security vulnerability has the potential to steal multiple users' cookies, gain unauthorized access to that user's account through stolen cookies, or redirect the user to other malicious websites...