PartKeepr
PartKeepr copied to clipboard
Cross-Site Scripting (XSS) in "/api/part_categories"
Bug description
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
Steps to reproduce
- Login as admin.
- Click on 'Add Category'.
- Insert XSS payload (<img src=1 onerror=alert('xss')>) in the "Name" field and click on Save.