# CVE-2024-41502
- **CVE:** CVE-2024-41502
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** Stored XSS via the form field "Observações" in the "Pessoas" section when creating or editing either a legal or a natural person. It is then executed whenever the person's profile containing the payload is loaded.
- **Payload**: `<img src=x onerror=alert(document.cookie)>`




Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view