HTML injection in email content during registration via FirstName/LastName parameter

Disclosed: 2021-12-18 09:42:30 By ibrahimatix0x01 To mtn_group
Medium
Vulnerability Details
## Summary: Hi, I just found an issue when register account in https://mtnmobad.mtnbusiness.com.ng/#/auth/registerUser It allows an attacker to inject malicious text include html code in email content. ## Steps To Reproduce: 1. Go to https://uat.id.manulife.ca/mortgagecreditor/register?ui_locales=en-CA. 1. Use the following payload as your First Name: 1. Put the following code as first name: ``` <h1>Ibrahim</h1> ``` 1. Fill other forms and submit {F1371367} ## Impact html code injection
Actions
View on HackerOne
Report Stats
  • Report ID: 1256496
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report