Stored Cross site scripting

Disclosed: 2016-06-28 05:06:54 By amirisme To zomato
Unknown
Vulnerability Details
hello zomato team, i have found a stored xss on https://www.zomato.com/beirut/garcias-dbayeh-metn step to reproduce -------------------------- 1- write a review by this payload : >'>"><img src=x onmouseover =prompt(document.domain)> 2-click edit 3- xss will excute :) video : https://youtu.be/ibawEBPQs3g best regaeds, Amir Ezat.
Actions
View on HackerOne
Report Stats
  • Report ID: 145246
  • State: Closed
  • Substate: duplicate
  • Upvotes: 8
Share this report