
Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in SolidInvoice Tax Rates, with exploitation steps and remediation guidance for version 2.3.7.
SolidInvoice is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates Feature. An authenticated attacker can inject arbitrary JavaScript into the application, which will then execute in users' browsers.
Exploitation allows a malicious user to store arbitrary JavaScript in the application, which will execute in the context of other authenticated users who view the Tax Rates page. If the application is deployed in a multi-user environment - for example, with multiple admins, this could lead to:
<image/src/onerror=prompt(1)>
Update SolidInvoice to version 2.3.8 or later.
Product: https://solidinvoice.co/