
Trudesk version 1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the tickets `Create/Modify Ticket Tags` on admin role.
Trudesk version 1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the tickets Create/Modify Ticket Tags on admin role.
The attacker must go to Settings menu, select tickets and then scroll down to find Ticket Tags. Click at CREATE and insert the XSS payload at the Add Tags input, Create Tag in order to exploit the stored XSS. The XSS payload will be launched immediately after save.
http://[IP]:8118/settings/tickets
POST
Trudesk version 1.2.6 (https://github.com/polonel/trudesk/releases/tag/v1.2.6)
Google Chrome Version 109.0.5414.119 (Official Build) (x86_64)
:shipit: Thapanarath Khempetch
Reference: