Skip to content

XSS on Hoosk v1.8 #63

Open
Open
@nhienit2010

Description

This vulnerability in edit page function

image

Exploit with using "heading" attribute, we can custom HTML tag lead to inject img tag with onerror event, and use HTML encoding to bypass filter some special chars

image

PoC
image

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions