XSS in Asset name

Disclosed: 2016-05-13 18:30:31 By ashish_r_padelkar To veris
Unknown
Vulnerability Details
Found one XSS iin asset name **Steps To Reproduce** 1. Create Any member at `https://sandbox.veris.in/portal/members/` 2. Add that member in any group at `https://sandbox.veris.in/portal/groups/` 3. Create an `Asset` named `<script>alert(1);</script>` at `https://sandbox.veris.in/portal/assets/` 4. Now go back to members `https://sandbox.veris.in/portal/members/` and click on the symbol shown in screen shot for any of the member {F88735} you should see an XSS popup! Regards Ashish
Actions
View on HackerOne
Report Stats
  • Report ID: 133744
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report