The application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded xss.sql, which uses SQL functionality to insert the XSS payload server-side.
This stored payload is later rendered unsafely in multiple backup management views without proper output encoding, leading to stored blind cross-site scripting (Blind XSS).
xss.sql which uses SQL functionality to insert a malicious XSS payload into the backup filename field server-side.Endpoints:
/backend/backup/upload/backend/backup//backup/{id}xss.sql via the Backup Upload functionality<img src=x onerror=alert(document.domain)>Avoid unsafe DOM manipulation methods: Do not use .html(), innerHTML, or similar sink functions in client-side JavaScript or server-side templating (e.g., PHP). Even when user input flowing into these sinks is not immediately apparent, they can introduce Cross-Site Scripting (XSS) vulnerabilities that an attacker may exploit.
Apply output encoding: Implement HTML entity encoding on all user-controlled data before rendering it in the browser. This helps neutralize potentially malicious input.
Implement input sanitization: Ensure that all user-supplied input is properly sanitized before processing or output. Currently, no sanitization mechanisms are in place, which should be addressed as a priority.
Enforce security headers and cookie attributes:
HttpOnly attribute on session cookies to prevent client-side script access.SameSite cookie attribute to mitigate Cross-Site Request Forgery (CSRF) risks.Secure attribute.These measures collectively reduce the impact of XSS and help prevent escalation paths such as CSRF via XSS.
https://mega.nz/file/eNFXgAAA#IETbPcKwr5vVLqJIAdc3uy4qgcVTgyPb_2HhB4zcwAE
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-01T22:04:21Z",
"nvd_published_at": "2026-04-01T22:16:19Z",
"severity": "CRITICAL"
}