Self-XSS Vulnerability on Password Reset Form

Disclosed: 2016-06-13 21:56:44 By idiablos To uber
Unknown
Vulnerability Details
Hello Security Team, I have found Third Security Vulnerability on your website :- https://partners.uber.com/ Vulnerability :-"XSS vulnerability on password reset time :)" My Payload is this :- >'>"><img src=x onmouseover =prompt(document.domain)> Following This Reproduce Steps :) 1) send password reset link on your email id 2) open password reset link 3) set as password this payload :- >'>"><img src=x onmouseover =prompt(document.domain)> 4) Continue and click on show password XSS got triaged Youtube Video Link :- https://youtu.be/UpUbq58LV9Y I request to you sir if this is not valid then close as informative please sir, am just reported this issue because this XSS on password reset time please sir:) If valid then I hope, you will FIX ASAP Regards, Pratik Panchal
Actions
View on HackerOne
Report Stats
  • Report ID: 125059
  • State: Closed
  • Substate: duplicate
  • Upvotes: 3
Share this report