- Status Closed
-
Assigned To
cbay - Private
Opened by malko - 09.10.2026
Last edited by cbay - 09.10.2026
FS#521 - Blind Cross-Site Scripting (XSS) via Contact Form — www.alwaysdata.com/en/contact/
Severity: High
Affected endpoint:
https://www.alwaysdata.com/en/contact/
Affected field(s):
“Name” field (confirmed), “Message” field (submitted, pending confirmation — see note below)
Vulnerability class:
Blind Stored XSS / HTML Injection (CWE-79)
Description:
The contact form on the above page does not appear to sanitize or encode user input before it is processed/stored/rendered elsewhere (e.g., in an internal admin panel, notification system, or email client used by staff). An HTML/JS payload submitted via the “Name” field triggered an out-of-band DNS callback to a Burp Collaborator server, confirming execution outside of my own browser session.
Proof of Concept:
The following payload was submitted in the “Name” field:
html
<img src="pleatfo27nan3vme473ekhdhy84zspge.oastify.com">
Evidence of execution:
The Collaborator server logged two separate DNS A-record lookups for the payload domain:
# Time (UTC) Type Source IP
17 2026-10-09 11:22:33.308 DNS 172.217.33.215
18 2026-10-09 11:22:33.331 DNS 172.253.1.218
The lookups occurred shortly after submission, from IPs distinct from my own testing IP, indicating the payload was parsed/rendered by a system other than the submitting browser (consistent with internal review tooling, a notification pipeline, or similar).
Steps to Reproduce:
1. Navigate to https://www.alwaysdata.com/en/contact/ 2. In the “Name” field, enter: <img src="[unique-id].oastify.com"> (or equivalent Collaborator/callback payload)
3. Fill remaining required fields with valid test data
4. Submit the form
5. Monitor the Collaborator/callback server for an inbound DNS/HTTP interaction
6. Observe the out-of-band callback confirming the payload was parsed as HTML outside the submitter’s own session
Impact:
If rendered in an internal tool without sanitization, this could allow an attacker to execute arbitrary JavaScript in the context of whatever system/staff session processes contact form submissions — potentially enabling session token theft, internal tool manipulation, or lateral exposure, depending on that system’s privileges.
Suggested remediation:
Sanitize/encode all contact form input before storage, display, or forwarding to any internal system (output encoding appropriate to the destination context — HTML-escape for HTML rendering, etc.).
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
blind xss alwaysdata.png
Hello,
Those IPs do not belong to us.
Kind regards,
Cyril