XSS Reflected on reddit.com via url path
High
Vulnerability Details
Hi I found a XSS-R
To reproduce the issue please click the poc link and then press the "verify email" button
PoC:
https://www.reddit.com/verification/asd',%20alert(document.location),%20%27
## Impact
With the help of XSS an attacker can steal your cookies, in many cases steal sessions, download malware onto your system and send a custom request.
Users can be socially engineered by the attacker by redirecting them from the real website to a fake one and there are many more attack scenarios that an expert attacker can perform with XSS.
It is also possible to inject html thus modifying the original page
Actions
View on HackerOneReport Stats
- Report ID: 1051373
- State: Closed
- Substate: resolved
- Upvotes: 144