Reflected XSS at yaman.olx.ph

Disclosed: 2016-07-18 10:16:16 By oldc4u53 To olx
Unknown
Vulnerability Details
Description of the Vulnerability ==================== Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. Vulnerable endpoint with Payload -------------------------------- ``` http://yaman.olx.ph/wp-content/themes/twentyfifteen/genericons/example.html#<img/src/onerror=alert(123)> ``` Recommended Fix ------------------------------------ Upgrade to the latest Wordpress Version or simply delete example.html from twentyfifteen theme.
Actions
View on HackerOne
Report Stats
  • Report ID: 151258
  • State: Closed
  • Substate: informative
  • Upvotes: 4
Share this report