From aa0900410bdcaac8767666359acb8384fdfffc37 Mon Sep 17 00:00:00 2001 From: duffyduck Date: Sun, 24 May 2026 15:38:16 +0200 Subject: [PATCH] Pentest 2026-05-24 Pen-31-Befunde (2x MEDIUM) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 31.1 Stored XSS in Vertragsfeldern: providerName, tariffName, priceFirst12Months, priceFrom13Months, priceAfter24Months nahmen rohe HTML-/Script-Payloads (