Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-13633 — Proof of concept for a blind/persistent XSS vulnerability in Blinger.io helpdesk, demonstrating remote code execution in admin panels via crafted messages. | Kitploit
Tools/GitHubGitHub/security-avs/cve-2019-13633
Vulnerability AnalysisWeb Application ExploitationInformation GatheringPhishingPenetration TestingSocial Engineering
GitHubsecurity-avs/cve-2019-13633

CVE-2019-13633

Proof of concept for a blind/persistent XSS vulnerability in Blinger.io helpdesk, demonstrating remote code execution in admin panels via crafted messages.

View Repository
285 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-13633

[Suggested description]: Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS.
[Additional Information]: Blinger.io - is a platform which used by global clients such as FxPro, Alfa Bank, OneTwoTrip, Ivi, KupiVIP Group, Belavia, Wargaming, Yandex, OZON, TCS Group Holding and others. Performing this attack allow criminals gather critical information about clients of targeted companies, and become basic point of many others attack vectors. An attacker can send arbitrary JavaScript code via a built-in communication channels, such as Telegram, WhatsApp, Viber, Skype, Facebook, and so on. Code is executed within follow panels:

  • conversations/all
  • conversations/inbox
  • conversations/unassigned
  • conversations/closed

[Vulnerability Type]: Cross Site Scripting (XSS)
[Vendor of Product]: https://blinger.io/
A letter was sent to the vendor about the vulnerability. Vulnerability was confirmed by vendor.
[Affected Component]:
https://app.blinger.io/conversations/all
https://app.blinger.io/conversations/inbox
https://app.blinger.io/conversations/unassigned
https://app.blinger.io/conversations/closed
[Affected Product Code Base]: Blinger Omnichannel helpdesk for customer support & sales - v.1.0.2519
[Attack Type]: Remote
[Impact Denial of Service]: False
[Impact Information Disclosure]: True
[Attack Vectors]:
Attacker send malicious JavaScript code via communication channels built-in the customer web page. Transmitted JavaScript code will be executed in the administration panel of Help Desk service, allowing attacker to steal session cookie, perform phishing attack, gathering critical information about customer clients, etc. : Alexander Semenenko, Luka Safonov. : Execution of malicious code and reflection in :


[Discovered]

[Reference]

https://blinger.io/

https://help.blinger.io/changelog

[Proof of Concept]

https://xsshunter.com/
stack Overflow
Download Tool