Dom Xss vulnerability

Disclosed: 2022-01-19 11:00:38 By fornex To recorded-future
High
Vulnerability Details
## Summary: Dom Xss vulnerability ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. Go to this link: https://api.recordedfuture.com/index.html 2. Open chrome devtool and go to console tab 3. Type: document.write('...<script>alert(1)</script>...'); 4. And boom! Alert 1! ## Impact XSS can have huge implications for a web application and its users. User accounts can be hijacked, credentials could be stolen, sensitive data could be exfiltrated, and lastly, access to your client computers can be obtained.
Actions
View on HackerOne
Report Stats
  • Report ID: 1448616
  • State: Closed
  • Substate: informative
  • Upvotes: 7
Share this report