[intensedebate.com] XSS Reflected POST-Based

Disclosed: 2021-01-15 21:20:46 By fuzzme To automattic
Low
Vulnerability Details
## Summary: Hello, i have found a XSS Reflected POST-Based in `https://www.intensedebate.com/ajax.php`. Vulnerable(s) URL : ```POST /https://www.intensedebate.com/ajax.php``` Vulnerable(s) Parameter(s): ``` $_POST['txt']; ``` Payload ``` azertyuiop<<><img+src="x"/onerror="prompt(document.cookie)"> ``` ##Steps to reproduce 1. Open the xss.html and will you see a javascript pop-up You can also follow me into the video POC. Thank you, good bye. ## Impact A attacker can perform a phishing attack or perform a CORS attack
Actions
View on HackerOne
Report Stats
  • Report ID: 1040533
  • State: Closed
  • Substate: resolved
  • Upvotes: 42
Share this report