Description
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when administrators or other users view the stored proposal, enabling cookie theft and malicious redirects.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
m0ze
References
www.exploit-db.com/exploits/47185 (ExploitDB-47185)
www.gigtodoscript.com (Official Product Homepage)
codecanyon.net/...todo-freelance-marketplace-script/23855397 (Product Reference)
www.vulncheck.com/...lance-marketplace-script-persistent-xss (VulnCheck Advisory: GigToDo Freelance Marketplace Script 1.3 Persistent XSS)