Error page Text Injection.
Unknown
Vulnerability Details
AS we can see in report an user or attacker is able to inject his text into error page and can trap to user to visit other site by adding following link /test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https://www.malicious.com%20so%20go%20to%20the%20new%20one%20since%20this%20one
A text injection and a missconfiguration of the 404 page which can be used in phishing.
POC URL: blog.trello.com/test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https:
URl:-https://www.phacility.com//test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https://www.malicious.com%20so%20go%20to%20the%20new%20one%20since%20this%20one
Actions
View on HackerOneReport Stats
- Report ID: 156196
- State: Closed
- Substate: not-applicable
- Upvotes: 4