We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Hello, i have found bug : Stored XSS on Milestones PM - Project and Task Management (project)
Steps
1- install the Application Milestones PM - Project and Task Management 2- go to (Projects) https://eu6.salesforce.com/a0C/o 3- create a new Projects like :https://eu6.salesforce.com/a0C580000008NOm (test) 4-on the Project like:(a0C580000008NOm) add new Milestones https://eu6.salesforce.com/a0B/e?CF00N58000005iDpI=test insert on the Project Milestone Name <img src="c" onerror=alert(document.cookie)> save it 5- open the project https://eu6.salesforce.com/a0C580000008NOm you will get XSS popup alert
<img src="c" onerror=alert(document.cookie)>
PoC video: https://www.dropbox.com/s/2tu6cqh8ivib52m/xssM.mp4?dl=0
i have reported it to salesforce team Thanks
The text was updated successfully, but these errors were encountered:
Fyi, this security issue was fixed in Milestones PM+. Milestones PM has not recently passed security review, but PM+ has.
On Jun 22, 2016 2:12 AM, "samir-dz" [email protected] wrote:
Hello, i have found bug : Stored XSS on Milestones PM - Project and Task Management (project) Steps 1- install the Application Milestones PM - Project and Task Management 2- go to (Projects) https://eu6.salesforce.com/a0C/o 3- create a new Projects like :https://eu6.salesforce.com/a0C580000008NOm (test) 4-on the Project like:(a0C580000008NOm) add new Milestones https://eu6.salesforce.com/a0B/e?CF00N58000005iDpI=test insert on the Project Milestone Name http://c save it 5- open the project https://eu6.salesforce.com/a0C580000008NOm you will get XSS popup alert PoC video: https://www.dropbox.com/s/2tu6cqh8ivib52m/xssM.mp4?dl=0 i have reported it to salesforce team Thanks — You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub #134, or mute the thread https://github.com/notifications/unsubscribe/AAwzFK9THfaOLIP6bRCzUZoxpAtt7Sigks5qONJpgaJpZM4I7cBX .
1- install the Application Milestones PM - Project and Task Management 2- go to (Projects) https://eu6.salesforce.com/a0C/o 3- create a new Projects like :https://eu6.salesforce.com/a0C580000008NOm (test) 4-on the Project like:(a0C580000008NOm) add new Milestones https://eu6.salesforce.com/a0B/e?CF00N58000005iDpI=test insert on the Project Milestone Name http://c save it 5- open the project https://eu6.salesforce.com/a0C580000008NOm you will get XSS popup alert
— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub #134, or mute the thread https://github.com/notifications/unsubscribe/AAwzFK9THfaOLIP6bRCzUZoxpAtt7Sigks5qONJpgaJpZM4I7cBX .
Sorry, something went wrong.
No branches or pull requests
Hello,
i have found bug : Stored XSS on Milestones PM - Project and Task Management (project)
1- install the Application Milestones PM - Project and Task Management
2- go to (Projects) https://eu6.salesforce.com/a0C/o
3- create a new Projects like :https://eu6.salesforce.com/a0C580000008NOm (test)
4-on the Project like:(a0C580000008NOm) add new Milestones
https://eu6.salesforce.com/a0B/e?CF00N58000005iDpI=test
insert on the Project Milestone Name
<img src="c" onerror=alert(document.cookie)>
save it
5- open the project https://eu6.salesforce.com/a0C580000008NOm
you will get XSS popup alert
PoC video: https://www.dropbox.com/s/2tu6cqh8ivib52m/xssM.mp4?dl=0
i have reported it to salesforce team
Thanks
The text was updated successfully, but these errors were encountered: