owncloud.com: Parameter pollution in social sharing buttons

Disclosed: 2016-03-14 12:19:11 By gorang_joshi To owncloud
Unknown
Vulnerability Details
Hello Owncloud ! For Example , We Have a Link : ``` https://owncloud.com/blog-you-can-soon-be-fined/ ``` And We Change It To :- ``` https://owncloud.com/blog-you-can-soon-be-fined/?u=https://vk.com&text=another_site:https://hackerone.com/gorang_joshi ``` So When You Share It , While Using Your Sharing Buttons Present On Your Page , The Source Code Will Change : Facebook : ```https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fowncloud.com%2Fblog-you-can-soon-be-fined%2F%3Fu%3Dhttps%3A%2F%2Fvk.com&text=another_site%3Ahttps%3A%2F%2Fhackerone.com%2Fgorang_joshi``` twitter :```https://twitter.com/intent/tweet?text=another_site%3Ahttps%3A%2F%2Fhackerone.com%2Fgorang_joshi&url=https%3A%2F%2Fowncloud.com%2Fblog-you-can-soon-be-fined%2F%3Fu%3Dhttps%3A%2F%2Fvk.com&original_referer=``` Thanks , The Same Report Was Reported By My Friend To Hackerone , You Can Check This Here : ``` https://hackerone.com/reports/105953 ``` Thanks , Hope You'll Response Likewise :)
Actions
View on HackerOne
Report Stats
  • Report ID: 106024
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report