Monica
cpe:2.3:a:monicahq:monica:*:*:*:*:*:*:*
- 4.1.2
A cross-site scripting (XSS) vulnerability has been identified in Monica version 4.1.2. This issue allows a malicious user to create a malformed contact and use it in the 'HOW YOU MET' customization options, triggering the XSS exploit.
Exploitation of this vulnerability allows for stored cross-site scripting, where the injected script is executed in the context of the user viewing the contact.
To reproduce this vulnerability, create a contact with a JavaScript payload in the name fields, ensuring to use double quotes for the payload. Then, select this contact in the 'HOW YOU MET' customization options and save the changes. The JavaScript payload will be executed when the contact is viewed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.