Web / CMS
Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0
Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0 ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site
.png)
Overview
Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0
ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site scripting attacks (XSS). The payload will trigger when a when a victim will visit the chatwindow page.
Vulnerability details
Cross Site Scripting (XSS) in username field in chatWindow functionality in ChatEngine 1.0 ThThe Application does not sanitize or escape username parameter, making it vulnerable to Stored cross-site scripting attacks (XSS).
Disclosure timeline
2023-04-01 Reported On
2023-07-06 Made Public On
Fixed On: Not Fixed
References
Credits
Akshat Singhal
















