Reflected XSS [██████]

Disclosed: 2022-04-29 14:06:38 By fdeleite To deptofdefense
Medium
Vulnerability Details
Reflected cross-site scripting (XSS) arises when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe way. An attacker can execute JavaScript arbitrary code on the victim's session. Steps To Reproduce Go to this URL: https://█████/7/0/33/1d/www.citysearch.com/search?what=x&where=place%22%3E%3Csvg+onload=confirm(document.domain)%3E ## Impact - Perform any action within the application that the user can perform. - View any information that the user is able to view. - Modify any information that the user is able to modify. - Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user. - Steal user's cookie.
Actions
View on HackerOne
Report Stats
  • Report ID: 1309385
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report