This advisory details a persistent XSS vulnerability in Feetan Inc WireShare v1.9.1 iOS, where the 'New Folder' input field fails to sanitize user input, allowing script injection. The PoC demonstrates how malicious script code executes in the folder index list and during deletion requests.
Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:Feetan Inc WireShare v1.9.1 iOS
No auth needed
Prerequisites:Access to the WireShare web interface (local or remote)