Reflected XSS on https://████/ (Bypass of #1002977)

Disclosed: 2020-11-23 18:10:40 By nagli To deptofdefense
Medium
Vulnerability Details
##Hello DoD team, Third time a charm :-) I really cannot explain what is going on with this ██████████ website, You just locked the report so i can't comment there, but it seems it works right now and i have proof of a video with time stamp. I am talking about #1002977, i hope you will see this fast enough when it still works. ███████ ##Summary: Reflected Cross site Scripting (XSS) on https://██████████████████ ##Steps To Reproduce: 1. Navigate to https://████████████ 2. Alert will pop :-) █████████ ##Recommendations for fix Content based escaping on the users input, in this case on the url parameter. ##Best Regards, nagli ## Impact Attacker can execute JS code on the Victim Behalf.
Actions
View on HackerOne
Report Stats
  • Report ID: 1010316
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report