Cross-Site Scripting Stored On Rich Media

Disclosed: 2016-11-17 09:26:40 By hussain_0x3c To pushwoosh
Unknown
Vulnerability Details
**Hi Team Security Pushwoosh** I'm Found Bug Cross-site Scripting Stored in On Rich Media . Steps to verify --- * . Login as **Attacker** * . Go To **Rich Media** and Create New Media * . Fill Name and Choose Zip Upload * . Upload **index.zip** in **Attachments** * . Cick Save and Enter to Media Waiting Page to Reload Payloads .. **XSS execute !!** POC --- PIC :- http://i.imgur.com/cOlh88C.png **Testing :- Firefox** **Regards** @Hussain
Actions
View on HackerOne
Report Stats
  • Report ID: 142540
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report