
Stored cross-site scripting (XSS) vulnerabilities in IngEstate Server v11.14.0
Affected API: Affected API: PUT /emgui/rest/appDatasheet//?full=true HTTP/1.1
To exploit this Stored Cross-Site Scripting (XSS) vulnerability, an authenticated user must first access the Software Package List page through the dashboard. The Edit feature interacts with the API endpoint /emgui/rest/appDatasheet/. An attacker can then inject an XSS payload into the 'About application', 'What's news', or 'Release note' parameters. Once injected, the malicious JavaScript is saved on the server and automatically executes when other users later view those sections.
An attacker can execute arbitrary JavaScript code in other users' browsers, leading to session hijacking, credential theft, or unauthorized actions performed on the victim's behalf. This vulnerability affects all users who view the compromised Software Package information.
Long Dang Hoang of Sacombank