Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stored HTML Injection in Servicedesk Module #8303

Open
raghavfaveo opened this issue Oct 3, 2024 · 0 comments
Open

Stored HTML Injection in Servicedesk Module #8303

raghavfaveo opened this issue Oct 3, 2024 · 0 comments
Assignees
Labels
Customer reported Bug Support Ticket and Customer reported bugs Paid This label considered as a Paid Product issues.

Comments

@raghavfaveo
Copy link

raghavfaveo commented Oct 3, 2024

  • Faveo Version : 9.2.0
  • Product Name : Faveo Helpdesk & Servicedesk (On-Premise and Cloud)
  • Reported By : Asad Iqbal
    Link: https://github.com/Asadiqbal2

Description:

Issue: The stored HTML payload when placed in the subject, identifier ,description of Problem gets executed after the Problem is created

More Details about issue:
Stored.HTML-Injection.pdf

Steps To Reproduce:

HTML Injection

  1. In the Problem add the HTML payload
    image

  2. View the problem after saving it
    image

@raghavfaveo raghavfaveo added Customer reported Bug Support Ticket and Customer reported bugs Paid This label considered as a Paid Product issues. labels Oct 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Customer reported Bug Support Ticket and Customer reported bugs Paid This label considered as a Paid Product issues.
Projects
None yet
Development

No branches or pull requests

3 participants