X2Engine / X2CRM

X2CRM Open Source CRM - PHP
http://www.x2crm.com
343 stars 166 forks source link

Stored XSS in module name #162

Closed Fadavvi closed 1 year ago

Fadavvi commented 6 years ago

Hi agian

Description : XSS in module name will prompt in all other pages of X2CRM CE V6.9

Sample Pic: ezgif-4-97e4273b25ba

Payload to use : "><img src=x onerror=prompt('@darknetguy');>

Tested on Windows 10 Firefox | Google Chrome // Cent-OS 7 Firefox | Chromium

BR,

Milad Fadavvi

pczupil commented 5 years ago

Thank you for the info Milad. We will have this fixed in our next release. I will keep this issue open until we have confirmed that the XSS has been removed.