Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/causefx/organizr/commit/a09d834d995599756b62016af7026d2408ecf43a | third party advisory patch |
https://huntr.dev/bounties/6059501f-05d2-4e76-ae03-5eb64835e6bf | exploit third party advisory patch |