Open GanbaruTobi opened 6 months ago
Hi
Just to check, is the issue related to this BCheck: https://github.com/PortSwigger/BChecks/blob/main/vulnerabilities-CVEd/CVE-2021-20323%20keycloak%20xss.bcheck
If you have any improvements to make, we'd love to see a pull request!
Current behavior
The check says that keycloak is vulnerable
Expected behavior
No warning for fixed versions
Motivation for change
Its not working as expected
Environment details
Additional details
The response contains an escaped xss payload instead of an unescaped:
...Unrecognized field \"<img src=x onerror=\"alert('Bo0oq')\"/>\ ...
But it would need to look like here: https://medium.com/@raia39499/how-i-exploit-cve-2021-20323-33d2f8d6826c