4 xss vulnerability dom based cwe 79 ; wordpress bootstrap.min.js is vulnerable

Disclosed: 2021-12-09 17:46:04 By rao_ji1hackerone To sifchain
Medium
Vulnerability Details
## Summary: I have found a bug in your site and the bug is xss vulnerability and it is in your wordpress bootstrap.min.js program. I also do manually test and I got the xss vulnearability There are totally I have found 4 vulnearability in your system and which are belong to 2018 To 2019 ## Steps To Reproduce: 1. Install retire.js extension in firefox browser 2. open your browser and redirect to your website . wait and check it gives you the full info 3. fuzz them by xss seclist directory it confirm the vulnerability * [attachment / reference] ## Impact A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired
Actions
View on HackerOne
Report Stats
  • Report ID: 1219002
  • State: Closed
  • Substate: duplicate
  • Upvotes: 1
Share this report