Description
Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
TaurusOmar
References
www.vulncheck.com/...freeter-persistent-cross-site-scripting
www.exploit-db.com/exploits/49833 (ExploitDB-49833)
freeter.io/ (Official Freeter Product Homepage)
imgur.com/a/iBuKWm4 (Proof of Concept Video)
www.vulncheck.com/...freeter-persistent-cross-site-scripting (VulnCheck Advisory: Freeter 1.2.1 - Persistent Cross-Site Scripting)