
Proof-of-concept for CVE-2024-40492: stored XSS vulnerability in heartbeat.chat leading to account takeover. Includes reproduction steps and impact analysis.
Stored Cross-Site Scripting (XSS) is a type of security vulnerability typically found in web applications. It occurs when an attacker is able to inject malicious scripts into a web application, and those scripts are stored on the server. When other users access the data containing the malicious script, the script is executed in their browsers.
giongfnef"><h1>test</h1>">
giongfnef">
giongfnef -> XSS is triggered -> this is stored XSS which can lead to Account Take OverLink POC to reproduce the exploit
After triggering the XSS, I can proceed with an Account Take Over. Since this is a stored XSS, any user who views the user section or searches for the user giongfnef will trigger the XSS and have their session stolen.
To prevent stored XSS vulnerabilities, follow these best practices:
Thanks for reading, have a nice day!