Reflected XSS on [█████████]

Disclosed: 2022-04-07 20:09:29 By saajanbhujel To deptofdefense
Medium
Vulnerability Details
## Summary: Hi security team members, I found a reflected XSS on the URL ## Impact 1. An attacker can steal the victim's cookies. 2. An attacker can execute JS code. ## System Host(s) █████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce 1. Navigate to this link:- https://██████████/██████=%3C/script%3E%3Cscript%3Ealert(document.domain)%3C/script%3E 2. Then, it will execute. ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1267380
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report