Menu

#82 XSS vulnerabilities

v1.0 (example)
open
nobody
9
2021-08-19
2021-08-19
No

We found there are several XSS vulnerabilities in WebChess. The attackers can inject malicous javascript code via the following paramaters:

  • . newMessage
  • . FromRow
  • . FromCol
  • etc.

We attached one of PoCs below.

1 Attachments

Discussion


Log in to post a comment.