Reflected XSS on ███?loc=

Disclosed: 2022-07-05 12:03:29 By 3amoura To ups
Medium
Vulnerability Details
Summary: ========= Detalis XSS ----------- Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it. ## Steps To Reproduce: 1. Go to Those Links. ███████ Filter input on arrival Encode data on output Use appropriate response headers Content Security Policy. These all are standards concepts for fix the XSS vulnerabilities. ## Impact screenshot: ████████ POC: ██████████
Actions
View on HackerOne
Report Stats
  • Report ID: 1536461
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report