Error Page Content Spoofing or Text Injection

Disclosed: 2021-06-15 23:51:36 By g4urav_19 To sifchain
Low
Vulnerability Details
i want to report a context spoofing or text injection at api-cryptoeconomics.sifchain.finance and market-data.sifchain.finance steps to reproduce: 1: Just browse this target on any browser 2: Target: https://api-cryptoeconomics.sifchain.finance/ 3: Then add any text or content after the "/" , i added this content 4: For example: !!!ATENTION!This_server_is_on_Maintenance_please_go_to_WWW.EVIL.COM 5: Now browser reflect the content or text which you add in url. Repeat the same process for https://market-data.sifchain.finance/ You can see also image which i had attached F1300496 F1300495 ## Impact Fix & Mitigation: Fix 404 error page to a new who not allow text content injection
Actions
View on HackerOne
Report Stats
  • Report ID: 1196253
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 2
Share this report