Open Akamai ARL XSS on http://media.████████

Disclosed: 2024-07-26 15:01:38 By renzi To deptofdefense
Medium
Vulnerability Details
**Description:** Hello, I found a Reflected Cross site Scripting (XSS) Open Akamai ARL on http://media.████, With this security flaw is possible executing JS codes... ## References https://owasp.org/www-community/attacks/xss/ https://community.akamai.com/customers/s/article/WebPerformanceV1V2ARLChangeStartingFebruary282021?language=en_US ## Impact The attacker can execute JS code. ## System Host(s) media.███ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Go to http://media.██████/7/0/33/1d/www.citysearch.com/search?what=x&where=place%22%3E%3Csvg+onload=confirm(document.domain)%3E ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1315898
  • State: Closed
  • Substate: resolved
  • Upvotes: 39
Share this report