Vulnerable Javascript library
Unknown
Vulnerability Details
Information disclosure:
So from simple lookup you can confirm the version of the jquery used.
And is a outdated one, that accordingly to some research i did, was public vulnerabilities, such as XSS.
Steps to reproduce:
1- navigate to: https://nextcloud.com/introducing-the-nextcloud-bug-bounty-program/
2- see sorce code
3- find /wp-content/cache/minify/000000/hY1BEoJADAQ_hMnKxfdEiFS2dhNNVgt9vYhcKY4zNT2dUHluSBHcAnPgi3U0x2oju8rHTz1cIEEV7RAp0wyT2VSY7hIwWF07LHJd6MeT_Y3nBei38OMgR5d2NNtK9CYqjWNwK2WVHRCVwvT__wU.js
4- navigate to: https://nextcloud.com/wp-content/cache/minify/000000/hY1BEoJADAQ_hMnKxfdEiFS2dhNNVgt9vYhcKY4zNT2dUHluSBHcAnPgi3U0x2oju8rHTz1cIEEV7RAp0wyT2VSY7hIwWF07LHJd6MeT_Y3nBei38OMgR5d2NNtK9CYqjWNwK2WVHRCVwvT__wU.js
5- find: jquery:"1.7.2"
Actions
View on HackerOneReport Stats
- Report ID: 145517
- State: Closed
- Substate: informative
- Upvotes: 5