Skip to content

Stored XSS with certain Vulnerability #1262

@estebanramos

Description

@estebanramos

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

The XSS Payload attached triggers an Stored XSS with the vulnerability Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting

{\"Test<img src=x onerror=alert(document.domain)>\":1}

Expected Behavior

No XSS payloads inside a Vulnerability Description should trigger the actual vulnerability

Steps To Reproduce

  1. Scan a Keycloak Target with 10.00 - 18.00 Version
  2. Go to Vulnerabilities
  3. The XSS is Triggered if Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting is found within Nuclei

Environment

- reNgine: 2.0.6
- OS: Kali 2024.1
- Python: 3.11.8
- Docker Engine: 20.10.25
- Docker Compose: 2.23.0
- Browser: Firefox 115.5.0

Anything else?

vuln1
vuln2

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions