Proof-of-concept for CVE-2024-41502: stored cross-site scripting (XSS) vulnerability in Jetimob Plataforma Imobiliaria CRM/ERP/CMS via the 'Observações' field in the Pessoas section.
Software: Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
Version: 20240627-0
Vulnerability: Stored Cross-Site Scripting (XSS)
Description: Stored XSS via the form field "Observações" in the "Pessoas" section when creating or editing either a legal or a natural person. It is then executed whenever the person's profile containing the payload is loaded.