# Affected software: Akeneo Online Demo
# Type of vulnerability: stored xss
# URL: http://www.akeneo.com/demo/
# Discovered by: Provensec
# Website: http://www.provensec.com
# Description:Akeneo is an open source Product Information Management
(PIM) system designed for retailers looking for efficient answers to
their multichannel needs.
# Proof of concept
username field of profile section was vulnerable to stored xss
http://demo.akeneo.com/#url=/user/profile/edit
edit the Username with payload "><img src=d onerror=confirm(1);> and
java script will execute
#screen http://prntscr.com/69ywwr