
Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in SolidInvoice client module, enabling session hijacking and arbitrary JavaScript execution for authenticated users.
SolidInvoice is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Client Module. An authenticated attacker can inject arbitrary JavaScript into the application, which will then execute in users' browsers.
Exploitation allows a malicious user to store arbitrary JavaScript in the application, which will execute in the context of other authenticated users who view the Clients page. If the application is deployed in a multi-user environment - for example, with multiple admins, this could lead to:
<script>prompt(document.cookie)</script>
Update SolidInvoice to version 2.3.8 or later.
Product: https://solidinvoice.co/