We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
XSS can be triggered via the Update Asset Index utility
XSS will be triggered
Json response volumes name makes triggers the payload
"session":{"id":1,"indexedVolumes":{"1":"\"<script>alert(26)</script>"},
It’s run on every POST request in the utility.
Resolved in 8c2ad0b
Summary
XSS can be triggered via the Update Asset Index utility
PoC
XSS will be triggered
Json response volumes name makes triggers the payload
It’s run on every POST request in the utility.
Resolved in 8c2ad0b