Reflected Cross Site scripting Attack (XSS)

Disclosed: 2016-10-20 11:49:47 By nileshsapariya To olx
Unknown
Vulnerability Details
Hi Team, Vulnerable URL :- https://olx.qa/en/account/confirm/?email=&hash=26d7e919ff37300d2f363c9066dd5b9d&ts=14682640390036a<script>alert(1)<%2fscript>261db&p=0674cd7dFl22cq3mM5jZfwjNxZ7slA==&vk=0&utm_source=test&utm_medium=email&utm_campaign=link XSS will be trigger. Well as you guys mentioned in the report #150735 that .qa might not be in scope Nevertheless reporting here to making the platform secure. And in a hope to get HOF ;) Regards, Nilesh S
Actions
View on HackerOne
Report Stats
  • Report ID: 150837
  • State: Closed
  • Substate: resolved
Share this report