
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
The attacker must create some ticket and then edit tags in the ticket and insert the XSS payload at the Add Tags input, Create Tag in order to exploit the stored XSS. The XSS payload will be launched immediately after save.
http://[ip]:8118/tickets/[ID]
POST
Trudesk version 1.2.6 (https://github.com/polonel/trudesk/releases/tag/v1.2.6)
Google Chrome Version 109.0.5414.119 (Official Build) (x86_64)
:shipit: Thapanarath Khempetch
Reference: