Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stored XSS with certain Vulnerability #1262

Open
1 task done
estebanramos opened this issue May 16, 2024 · 1 comment
Open
1 task done

Stored XSS with certain Vulnerability #1262

estebanramos opened this issue May 16, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@estebanramos
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

The XSS Payload attached triggers an Stored XSS with the vulnerability Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting

{\"Test<img src=x onerror=alert(document.domain)>\":1}

Expected Behavior

No XSS payloads inside a Vulnerability Description should trigger the actual vulnerability

Steps To Reproduce

  1. Scan a Keycloak Target with 10.00 - 18.00 Version
  2. Go to Vulnerabilities
  3. The XSS is Triggered if Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting is found within Nuclei

Environment

- reNgine: 2.0.6
- OS: Kali 2024.1
- Python: 3.11.8
- Docker Engine: 20.10.25
- Docker Compose: 2.23.0
- Browser: Firefox 115.5.0

Anything else?

vuln1
vuln2

@estebanramos estebanramos added the bug Something isn't working label May 16, 2024
Copy link

👋 Hi @estebanramos,
Issues is only for reporting a bug/feature request. Please read documentation before raising an issue https://rengine.wiki
For very limited support, questions, and discussions, please join reNgine Discord channel: https://discord.gg/azv6fzhNCE
Please include all the requested and relevant information when opening a bug report. Improper reports will be closed without any response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant