# Question - Stored XSS Vulnerability

**URL:** https://discussions.eramba.org/t/question-stored-xss-vulnerability/2326
**Category:** Forum - Software
**Tags:** bug
**Created:** [October 12, 2022, 1:50pm UTC](https://discussions.eramba.org/t/question-stored-xss-vulnerability/2326 "2022-10-12T13:50:43Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![okankurtulus](https://discussions.eramba.org/letter_avatar_proxy/v4/letter/o/8491ac/32.png) [@okankurtulus](https://discussions.eramba.org/u/okankurtulus)
#### Post date: [October 12, 2022, 1:50pm UTC](https://discussions.eramba.org/t/question-stored-xss-vulnerability/2326/1 "2022-10-12T13:50:43Z")

</div>

Hello,  
While examining the platform, I saw that an input field could not be sanitized cleanly. I found that I could run JavaScript commands on the system when I sent the Stored XSS payload to the relevant input. I tried with unauthorized users, but you can only perform this vulnerability with an authorized user.

**1-)** Login to the system with an authorized user. The “Add” operation is performed with the “Actions” button in the upper right of the Dashboard.

**2-)** While adding, the following XSS payload is sent to the “KPI Title” input.

Payload:

`</sCriPt><sCriPt>alert(1);</sCriPt>`

**3-)** When you come to the Dashboard screen after the addition is made, you will see that the relevant Alert command is running.

App Version:  
c2.8.1

I cannot upload PoC Screen Shots as I am a new user.

---

<div class="post-metadata">

### Author: ![sam](https://discussions.eramba.org/letter_avatar_proxy/v4/letter/s/5f9b8f/32.png) [@sam](https://discussions.eramba.org/u/sam)
#### Post date: [October 12, 2022, 1:53pm UTC](https://discussions.eramba.org/t/question-stored-xss-vulnerability/2326/2 "2022-10-12T13:53:28Z")

</div>

Hello,

Thanks for reporting.  
This issue is already fixed in the enterprise, and the new community will have this fixed as well.
