Headline
CVE-2022-43142: BugReport/XssBug.md at main · TongJinBo/BugReport
A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
Permalink
1 contributor
Users who have contributed to this file
Bug Submitter: 佟金波
Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the add-fee.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
vendors: sourcecodester.com;
Vulnerability location: /psa_php/api.php?action=save
[+] Payload:
"><script>alert(1)</script>
Please execute the Payload provided above, as shown in the following figure: