Reflected XSS [███]
Medium
Vulnerability Details
Reflected cross-site scripting (XSS) arises when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe way. An attacker can execute JavaScript arbitrary code on the victim's session.
Steps To Reproduce
Go to this URL:
https://████████/7/0/33/1d/www.citysearch.com/search?what=x&where=place%22%3E%3Csvg+onload=confirm(document.domain)%3E
## Impact
- Perform any action within the application that the user can perform.
- View any information that the user is able to view.
- Modify any information that the user is able to modify.
- Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.
- Steal user's cookie.
Actions
View on HackerOneReport Stats
- Report ID: 1309237
- State: Closed
- Substate: resolved
- Upvotes: 3