Reflected XSS on https://█████████/

Disclosed: 2021-02-01 17:47:32 By nagli To deptofdefense
Medium
Vulnerability Details
##Vulnerable Website URL or Application: ```javascript https://███████/███████=%22%3E%3Csvg/onload=alert(%22nagli%22)%3E ``` ##Description of Security Issue: (please limit to one site/app per submission) Reflected XSS due to no input validation ██████████ ##Steps needed to reproduce bug: Navigate to ```javascript https://███████/█████████=%22%3E%3Csvg/onload=alert(%22nagli%22)%3E ``` Choose whatever javascript you'd like to execute on the sub_div_ofc_sym_cd query parameter ##Remediation Sanitize the input on the that parameter ##Best Regards nagli ## Impact Executing Javascript on behalf of the victim
Actions
View on HackerOne
Report Stats
  • Report ID: 1065167
  • State: Closed
  • Substate: resolved
  • Upvotes: 16
Share this report