
CVE-2022-23861: Multiple Stored Cross-Site Scripting in YSoft SafeQ
Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.
This vulnerability was found in collaboration with Marian-Razvan Ilisanu.
The disclosure for this vulnerability can be found here.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.