Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC_CVE-2024-40492 — Proof-of-concept for CVE-2024-40492: stored XSS vulnerability in heartbeat.chat leading to account takeover. Includes reproduction steps and impact analysis. | Kitploit
Tools/GitHubGitHub/minendie/poc_cve-2024-40492
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubminendie/poc_cve-2024-40492

POC_CVE-2024-40492

Proof-of-concept for CVE-2024-40492: stored XSS vulnerability in heartbeat.chat leading to account takeover. Includes reproduction steps and impact analysis.

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-40492: Stored XSS to ATO

Description

Stored Cross-Site Scripting (XSS) is a type of security vulnerability typically found in web applications. It occurs when an attacker is able to inject malicious scripts into a web application, and those scripts are stored on the server. When other users access the data containing the malicious script, the script is executed in their browsers.

Steps to Reproduce

  1. Go to https://app.heartbeat.chat/
  2. Create an account with the following details:
    • First name:
      giongfnef"><h1>test</h1>">
      
    • Last name:
      giongfnef">
      
  3. Go to "Threads" then search for the first name giongfnef -> XSS is triggered -> this is stored XSS which can lead to Account Take Over

POC

Link POC to reproduce the exploit

Impact

After triggering the XSS, I can proceed with an Account Take Over. Since this is a stored XSS, any user who views the user section or searches for the user giongfnef will trigger the XSS and have their session stolen.

Mitigation

To prevent stored XSS vulnerabilities, follow these best practices:

  • Input Validation: Validate and sanitize all user inputs on the server-side.
  • Output Encoding: Encode data before displaying it in the browser to prevent execution of injected scripts.
  • Use Security Libraries: Use libraries and frameworks that automatically handle input sanitization and output encoding.
  • Content Security Policy (CSP): Implement CSP headers to restrict the sources from which scripts can be loaded.

Thanks for reading, have a nice day!

Download Tool