Reflected XSS on https://████/ (Bypass of #1002977)
Medium
Vulnerability Details
##Hello DoD team,
Third time a charm :-)
I really cannot explain what is going on with this ██████████ website,
You just locked the report so i can't comment there, but it seems it works right now and i have proof of a video with time stamp.
I am talking about #1002977, i hope you will see this fast enough when it still works.
███████
##Summary:
Reflected Cross site Scripting (XSS) on https://██████████████████
##Steps To Reproduce:
1. Navigate to https://████████████
2. Alert will pop :-)
█████████
##Recommendations for fix
Content based escaping on the users input, in this case on the url parameter.
##Best Regards,
nagli
## Impact
Attacker can execute JS code on the Victim Behalf.
Actions
View on HackerOneReport Stats
- Report ID: 1010316
- State: Closed
- Substate: resolved
- Upvotes: 10