# CVE-2024-41503
- **CVE:** CVE-2024-41503
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** The "Busca" (search) function used throughout the application contains a filter option that can be saved - when saving it, there is a "Título" form field that allows injection of JavaScript code, storing the code in the application. It is then executed when the filter is created or when clicking to delete it, when the deletion confirmation window containing the payload appears.
- **Payload:** `<img src=x onerror=alert(document.cookie)>`



[4.0K] /data/pocs/94385adbf03d35cecc17c90ab9460adf736b680c
├── [4.0K] img
│ ├── [125K] 1.png
│ ├── [106K] 2.png
│ └── [123K] 3.png
└── [ 699] README.md
1 directory, 4 files