Skip to content

Thirukrishnan/CVE-2023-33408

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 

Repository files navigation

CVE-2023-33408

Minical 1.0.0 is vulnerable to Stored Cross-Site Scripting (XSS)

Vendor: https://github.com/minical/minical
Demo Application: https://demo.minical.io/


PoC

Step 1: Log in to the Minical Application and Navigate to Room->Room Status.

image

Step 2: Click on the Edit Room Note option and enter the payload.
Payload= <svg onload=alert(document.location)<!--

image

Step 3: Click on Save Changes and observe the payload getting triggered.

image

image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published