HTBox / crisischeckin

Crisischeckin Humanitarian Toolbox repository
Apache License 2.0
173 stars 157 forks source link

Crisis Checkin login page appears vulnerable to cross-site scripting #715

Open 333JeremySloan opened 6 years ago

333JeremySloan commented 6 years ago

It looks like login input fields are not being properly sanitized.

Steps to reproduce:

Access https://crisischeckin-d.azurewebsites.net/Account/Login

Enter one of the following values as username: <SCript> &#39;

Result: Server returns full stack trace error