Monica Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Monica version 4.1.2. This issue allows a malicious user to create a malformed contact and use it in the 'HOW YOU MET' customization options, triggering the XSS exploit.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where the injected script is executed in the context of the user viewing the contact.

Reproduction

To reproduce this vulnerability, create a contact with a JavaScript payload in the name fields, ensuring to use double quotes for the payload. Then, select this contact in the 'HOW YOU MET' customization options and save the changes. The JavaScript payload will be executed when the contact is viewed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.