A persistent cross-site scripting (XSS) vulnerability exists in gugoan's Economizzer v.0.9-beta1 The application fails to properly sanitize user-supplied input when creating a new cash book entry via the *cashbook/create* endpoint. An attacker can inject malicious JavaScript payloads that are permanently stored and later executed in the context of any user who views the affected entry. https:///web/cashbook/create POST /web/cashbook/create HTTP/2 Host: - ------WebKitFormBoundaryM93AAtGLA59fTnSU --snip--