Summary #
Stored XSS affects users with the administrator role or a with a role with the PoolList and PoolView resources assigned via the LabelFormat field. In the Pools / Add pool, add the XSS payload in the labelFormat field. The payload gets executed when clicking on the pool details and running Update pool.
General information #
Description: The LabelFormat field within Pools / Add pool is vulnerable to Stored Cross-Site Scripting (XSS).
Versions Affected: 1.0.0 through 6.5.1
Version Fixed: 6.5.2
Researcher: HEKK.ONE
Proof-of-Concept (POC) Exploit #
Go to Pools and click on Add pool.
Now give the pool a name (ex. name) ,select a pooltype and add the XSS payload in the LabelFormat field, ex. <script>prompt()</script>. Now click on Create.
The pool is created, click OK.
Click on the Details button of newly created pool name.
Now click on Update pool to execute the XSS payload.
This vulnerability works for users with the administrator role or a with a role with the PoolList and PoolView resources assigned.