# CVE-2024-41504
- **CVE:** CVE-2024-41504
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** In the "Oportunidades" section of the application when creating or editing an "Atividade" (activity), the form field "Descrição" allows injection of JavaScript code. It is then executed whenever the activity containing the payload is loaded.
- **Payload:** `<img src=x onerror=alert(document.cookie)>`


[4.0K] /data/pocs/f32f8b83133660f25c4f3278971e1c6b642f99fd
├── [4.0K] img
│ ├── [171K] 1.png
│ └── [101K] 2.png
└── [ 543] README.md
1 directory, 3 files