Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
CVE-2024-41505 — Proof-of-concept for CVE-2024-41505: Stored Cross-Site Scripting (XSS) in Jetimob Plataforma Imobiliaria via the 'Profissão' field, executing on profile load. | Kitploit
Proof-of-concept for CVE-2024-41505: Stored Cross-Site Scripting (XSS) in Jetimob Plataforma Imobiliaria via the 'Profissão' field, executing on profile load.
Software: Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
Version: 20240627-0
Vulnerability: Stored Cross-Site Scripting (XSS)
Description: Stored XSS in the "Pessoas" section via the field "Profissão" when creating or editing a natural person. It is then executed whenever the person's profile containing the payload is loaded.