Vulnerable Javascript library

Disclosed: 2016-06-17 19:19:22 By paulochoupina To nextcloud
Unknown
Vulnerability Details
Information disclosure: So from simple lookup you can confirm the version of the jquery used. And is a outdated one, that accordingly to some research i did, was public vulnerabilities, such as XSS. Steps to reproduce: 1- navigate to: https://nextcloud.com/introducing-the-nextcloud-bug-bounty-program/ 2- see sorce code 3- find /wp-content/cache/minify/000000/hY1BEoJADAQ_hMnKxfdEiFS2dhNNVgt9vYhcKY4zNT2dUHluSBHcAnPgi3U0x2oju8rHTz1cIEEV7RAp0wyT2VSY7hIwWF07LHJd6MeT_Y3nBei38OMgR5d2NNtK9CYqjWNwK2WVHRCVwvT__wU.js 4- navigate to: https://nextcloud.com/wp-content/cache/minify/000000/hY1BEoJADAQ_hMnKxfdEiFS2dhNNVgt9vYhcKY4zNT2dUHluSBHcAnPgi3U0x2oju8rHTz1cIEEV7RAp0wyT2VSY7hIwWF07LHJd6MeT_Y3nBei38OMgR5d2NNtK9CYqjWNwK2WVHRCVwvT__wU.js 5- find: jquery:"1.7.2"
Actions
View on HackerOne
Report Stats
  • Report ID: 145517
  • State: Closed
  • Substate: informative
  • Upvotes: 5
Share this report