Cross-site Scripting (XSS) - Reflected on http://h1b4e.n2.ips.mtn.co.ug:8080 via Nginx-module

Disclosed: 2024-08-24 11:23:09 By renzi To mtn_group
Medium
Vulnerability Details
## Summary: Hello, I found a Reflected Cross site Scripting (XSS) on http://h1b4e.n2.ips.mtn.co.ug:8080 . With this security flaw is possible rewrite the content of page, executing JS codes... ## Steps To Reproduce: How we can reproduce the issue: 1. Go to http://h1b4e.n2.ips.mtn.co.ug:8080/status%3E%3Cscript%3Ealert(31337)%3C%2Fscript%3E 2. We can see alert message 31337 {F1259889} ## Supporting Material/References: * https://owasp.org/www-community/attacks/xss/ ## Impact * The attacker can execute JS code. * Rewrite the content of Page
Actions
View on HackerOne
Report Stats
  • Report ID: 1159362
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report