PT-2026-46209 · Gigtodoscript · Gigtodo
M0Ze
·
Published
2026-06-04
·
Updated
2026-06-04
·
CVE-2019-25739
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create proposal endpoint that execute when administrators or other users view the stored proposal, enabling cookie theft and malicious redirects.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gigtodo