crisischeckin icon indicating copy to clipboard operation
crisischeckin copied to clipboard

Crisis Checkin login page appears vulnerable to cross-site scripting

Open 333JeremySloan opened this issue 7 years ago • 0 comments

It looks like login input fields are not being properly sanitized.

Steps to reproduce:

Access https://crisischeckin-d.azurewebsites.net/Account/Login

Enter one of the following values as username: <SCript> &#39;

Result: Server returns full stack trace error

333JeremySloan avatar Oct 04 '18 18:10 333JeremySloan