# CVE-2024-41502
- **CVE:** CVE-2024-41502
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** Stored XSS via the form field "Observações" in the "Pessoas" section when creating or editing either a legal or a natural person. It is then executed whenever the person's profile containing the payload is loaded.
- **Payload**: `<img src=x onerror=alert(document.cookie)>`




[4.0K] /data/pocs/5d4fc0e0c364a708a34f99db0ce6620c099a93b7
├── [4.0K] img
│ ├── [120K] 1.png
│ ├── [137K] 2.png
│ ├── [ 99K] 3.png
│ └── [ 94K] 4.png
└── [ 552] README.md
1 directory, 5 files