The application contains a critical cross-site scripting (XSS) vulnerability in the debug logging functionality. User-controlled content is
inserted directly into the DOM via innerHTML without any sanitization.
I think the danger of this vulnerability lies in that once a malicious third-party extension is loaded, both local and remote services
(i.e. the drawnix service on your official website) will be affected, and user data will not be protected.
apps/web/src/app/app.tsx
(window as any)['__drawnix__web__console'] = (value: string) => {
addDebugLog(board, value);
};
If you want to simply test whether this vulnerability exists, you can enter a verification payload in the browser console interface:
window.__drawnix__web__console('<img src=x onerror=alert("XSS")>');
The application contains a critical cross-site scripting (XSS) vulnerability in the debug logging functionality. User-controlled content is
inserted directly into the DOM via innerHTML without any sanitization.
I think the danger of this vulnerability lies in that once a malicious third-party extension is loaded, both local and remote services
(i.e. the drawnix service on your official website) will be affected, and user data will not be protected.
apps/web/src/app/app.tsx
If you want to simply test whether this vulnerability exists, you can enter a verification payload in the browser console interface: