Reported on

Dec 30th 2022


After login to portal create a new post and type the following text with XSS payload

bypass of this fix

Proof of Concept

Login to portal.
create a post with xss paylaod
save it

Bypass Payload

/*/**<input type="text" value=`` <div/onmouseover='alert(1)'>X</div>**/*/*

Users & admin account takeover

