Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by wickedwolve - 29.08.2025
Last edited by cbay - 08.09.2025

FS#207 - reflected XSS at admin.alwaysdata.com

Hello there,

i found an XSS vulnerability affecting "addresses" JSON parameter in a POST request to admin.alwaysdata.com/site/resolver.
i have to apologies I didn't get around including a custom header before i found the bug, I'm hopeful this will be overlooked on my part
my POC Is attached below pretty neet and straightforward and includes my IP as requested in POC guidelines. cheers.

:)

Closed by  cbay
08.09.2025 07:05
Reason for closing:  Invalid

Hello,
I wanted to confirm that the payload I submitted is (`<script>alert(document.domain)</script>`) does indeed execute in the browser.
I also tested with `<script>alert(1)</script>` and observed the alert popup, which confirms this is an exploitable XSS issue.
i am sorry this is my first report

Please let me know if you need additional details.
Best regards,
Chris,
[Your Email]

Admin
cbay commented on 29.08.2025 08:01

Hello,

This is a self-XSS, so not exploitable by an attacker.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing