Monkeytype
cpe:2.3:a:monkeytype:monkeytype:*:*:*:*:*:*:*
- <= 25.36.0
A cross-site scripting (XSS) vulnerability has been identified in Monkeytype, a customizable typing test application, in versions through 25.36.0. The issue arises from improper handling of user input when loading saved custom text, allowing for the execution of malicious scripts.
Exploitation of this vulnerability allows for self-cross-site scripting, where the injected script executes in the context of the user who created the custom text.
To reproduce this vulnerability, enter custom mode and save a new custom text file. When prompted to name the file, enter a payload, such as an image tag with an 'onerror' event. After saving, the payload will execute.
Users can update to version 25.36.1 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.