Centraleyezer: Stored XSS using HTML Entities — [CVE-2019–12299] Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.
I could bypass the restrictions using HTML Entities > <, the Stored XSS only triggers when editing the category. More Information: https://link.medium.com/5galrOpMy1 _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
