Full Disclosure mailing list archives
Centraleyezer: Stored XSS using HTML Entities — [CVE-2019–12299]
From: infinitybuzz via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 12 Nov 2019 16:40:43 +0000
Centraleyezer: Stored XSS using HTML Entities — [CVE-2019–12299] Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section. I could bypass the restrictions using HTML Entities > <, the Stored XSS only triggers when editing the category. More Information: https://link.medium.com/5galrOpMy1 _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Centraleyezer: Stored XSS using HTML Entities — [CVE-2019–12299] infinitybuzz via Fulldisclosure (Nov 15)