|
Task Description
Severity: High
Affected endpoint: https://www.alwaysdata.com/en/contact/
Affected field(s): “Name” field (confirmed), “Message” field (submitted, pending confirmation — see note below)
Vulnerability class: Blind Stored XSS / HTML Injection (CWE-79)
Description: The contact form on the above page does not appear to sanitize or encode user input before it is processed/stored/rendered elsewhere (e.g., in an internal admin panel, notification system, or email client used by staff). An HTML/JS payload submitted via the “Name” field triggered an out-of-band DNS callback to a Burp Collaborator server, confirming execution outside of my own browser session.
Proof of Concept: The following payload was submitted in the “Name” field:
html <img src="pleatfo27nan3vme473ekhdhy84zspge.oastify.com">
Evidence of execution: The Collaborator server logged two separate DNS A-record lookups for the payload domain:
# Time (UTC) Type Source IP 17 2026-10-09 11:22:33.308 DNS 172.217.33.215 18 2026-10-09 11:22:33.331 DNS 172.253.1.218
The lookups occurred shortly after submission, from IPs distinct from my own testing IP, indicating the payload was parsed/rendered by a system other than the submitting browser (consistent with internal review tooling, a notification pipeline, or similar).
Steps to Reproduce:
1. Navigate to https://www.alwaysdata.com/en/contact/ 2. In the “Name” field, enter: <img src="[unique-id].oastify.com"> (or equivalent Collaborator/callback payload) 3. Fill remaining required fields with valid test data 4. Submit the form 5. Monitor the Collaborator/callback server for an inbound DNS/HTTP interaction 6. Observe the out-of-band callback confirming the payload was parsed as HTML outside the submitter’s own session
Impact: If rendered in an internal tool without sanitization, this could allow an attacker to execute arbitrary JavaScript in the context of whatever system/staff session processes contact form submissions — potentially enabling session token theft, internal tool manipulation, or lateral exposure, depending on that system’s privileges.
Suggested remediation: Sanitize/encode all contact form input before storage, display, or forwarding to any internal system (output encoding appropriate to the destination context — HTML-escape for HTML rendering, etc.).
|