Reflected XSS at https://██████████/████████ via "███████" parameter

Disclosed: 2022-02-14 21:20:46 By pelegn To deptofdefense
Medium
Vulnerability Details
There is Reflected Cross site scripting issue at the following url: https://████████/█████ Proof Of Concept https://████/███?███=%22onfocus%3d%22alert(document.domain)%22autofocus%3d%22&submit=Search ███ Best Regards @pelegn ## Impact Cookies Exfiltration SOAP Bypass CORS Bypass Executing javascript on the victim behalf ## System Host(s) ██████████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Navigate to https://███████/████████?███████=%22onfocus%3d%22alert(document.domain)%22autofocus%3d%22&submit=Search ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1457493
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report