Reflected xss in https://sh.reddit.com

Disclosed: 2022-05-08 07:36:43 By abhiramsita To reddit
High
Vulnerability Details
## Summary: Reflected cross-site scripting (or XSS) arises when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe way. ## Impact: attacker can execute malicious java script and steal cookies ## Steps To Reproduce: [add details for how we can reproduce the issue] Hi team , Navigate to below url scroll to page end find a option see more Move mouse over there and observe the execution of javascript ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact attacker can execute malicious java script and steal cookies
Actions
View on HackerOne
Report Stats
  • Report ID: 1549206
  • State: Closed
  • Substate: resolved
  • Upvotes: 146
Share this report