monicahq / docker

docker image of Monica

Home Page:https://hub.docker.com/_/monica/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

stored XSS in "http://<APP-IP>/people/<ID>/avatar"

d4rks1d33 opened this issue · comments

Is possible to perform a stored XSS uploading a malicious image

Let me know if you need more information about this bug and how to reproduced it

Please send any detail to security@monicahq.com