cross site scripting in : mtn.bj

Disclosed: 2022-08-06 11:19:10 By alimanshester To mtn_group
High
Vulnerability Details
## Summary: Xss vulnerability in mtn.bj in file name ## Steps To Reproduce: 1.Go to : https://www.mtn.bj/business/ressources/formulaires/plan-de-localisation-de-compte/?next=https://www.mtn.bj/business/ressources/formulaires/formulaire-de-souscription/ 2 - fill all inputs with any data 3 - in file upload upload a file with payload file name such as : "><img src=x onerror=alert(document.cookie);.jpg 4-the payload will executed in the page . ## Supporting Material/References: 1 - video showing poc 2 - screen shot ## Impact execute malicious java script in user browser
Actions
View on HackerOne
Report Stats
  • Report ID: 1264834
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report