Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Package
ci4-cms-erp/ci4ms
(bertugfahri/ci4ms)
Affected versions
<=0.31.1.0
Patched versions
0.31.2.0
An attacker can acheive Full Account Takeover & Privilege Escalation via Stored DOM Blind XSS on public-facing landing pages through the System Settings Company Information section which allows the injection of XSS payloads