Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by malko - 09.10.2026
Last edited by cbay - 09.10.2026

FS#521 - Blind Cross-Site Scripting (XSS) via Contact Form — www.alwaysdata.com/en/contact/

Severity: High

Affected endpoint:
https://www.alwaysdata.com/en/contact/

Affected field(s):
“Name” field (confirmed), “Message” field (submitted, pending confirmation — see note below)

Vulnerability class:
Blind Stored XSS / HTML Injection (CWE-79)

Description:
The contact form on the above page does not appear to sanitize or encode user input before it is processed/stored/rendered elsewhere (e.g., in an internal admin panel, notification system, or email client used by staff). An HTML/JS payload submitted via the “Name” field triggered an out-of-band DNS callback to a Burp Collaborator server, confirming execution outside of my own browser session.

Proof of Concept:
The following payload was submitted in the “Name” field:

html
<img src="pleatfo27nan3vme473ekhdhy84zspge.oastify.com">

Evidence of execution:
The Collaborator server logged two separate DNS A-record lookups for the payload domain:

# Time (UTC) Type Source IP
17 2026-10-09 11:22:33.308 DNS 172.217.33.215
18 2026-10-09 11:22:33.331 DNS 172.253.1.218

The lookups occurred shortly after submission, from IPs distinct from my own testing IP, indicating the payload was parsed/rendered by a system other than the submitting browser (consistent with internal review tooling, a notification pipeline, or similar).

Steps to Reproduce:

1. Navigate to https://www.alwaysdata.com/en/contact/ 2. In the “Name” field, enter: <img src="[unique-id].oastify.com"> (or equivalent Collaborator/callback payload)
3. Fill remaining required fields with valid test data
4. Submit the form
5. Monitor the Collaborator/callback server for an inbound DNS/HTTP interaction
6. Observe the out-of-band callback confirming the payload was parsed as HTML outside the submitter’s own session

Impact:
If rendered in an internal tool without sanitization, this could allow an attacker to execute arbitrary JavaScript in the context of whatever system/staff session processes contact form submissions — potentially enabling session token theft, internal tool manipulation, or lateral exposure, depending on that system’s privileges.

Suggested remediation:
Sanitize/encode all contact form input before storage, display, or forwarding to any internal system (output encoding appropriate to the destination context — HTML-escape for HTML rendering, etc.).

Closed by  cbay
09.10.2026 12:58
Reason for closing:  Invalid
Admin
cbay commented on 09.10.2026 12:58

Hello,

# Time (UTC) Type Source IP
> 17 2026-10-09 11:22:33.308 DNS 172.217.33.215
> 18 2026-10-09 11:22:33.331 DNS 172.253.1.218

Those IPs do not belong to us.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing