We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
In reNgine v1.0, there is Stored Cross-site Scripting before deleting a Scan Engine!
/scanEngine/
');alert('XSSed by Binit at '+document.location+'!');//
Here, the payload will be executed through the values inside the onclick attribute, as shown in the image below:
The text was updated successfully, but these errors were encountered:
412c5ce
No branches or pull requests
Issue Summary
In reNgine v1.0, there is Stored Cross-site Scripting before deleting a Scan Engine!
Steps to Reproduce
/scanEngine/
endpoint.');alert('XSSed by Binit at '+document.location+'!');//
in the Engine name field.Here, the payload will be executed through the values inside the onclick attribute, as shown in the image below:
Technical details
The text was updated successfully, but these errors were encountered: