Closed Pegasus0xx closed 1 year ago
Experience names are allowed to include HTML tags (certain competitions require far more elaborate names such as with images). Experience levels are only maintained maintained by the administrators so this is intended for the frontend.
For the backend can you please try again with the fix from the previous issue and see if fixes it?
it fixed 👍🏻
I leave this open since it exposed another issue with the backend Help
widget which doesnt properly escape the model details.
A fix for this has been merged. Can you please confirm that the issue is fixed in the backend? fyi: the frontend stayed as is
issue not fixed, there another issue after login to "echoCTF Management interface" you see alert msg
I cant confirm the Experience issue, i think you managed to pull the images before the build completed :sob: terribly sorry about that, can you please pull again and check the experience issue?
I will address the dashboard on another PR.
it fixed experience issue
Sorry closed by accident.
The fix for the dashboard XSS is merged, can you please pull updated images and confirm its fixed? :heart:
The dashboard XSS has been fixed.
Hey @proditis :wave: ,
There's a XSS has been found in the backend this vulnerability has been affecting the frontend.
Steps To Reproduce:
PoC:
Best Regards, Pegasus