these are my old reports and still i have not receive any good replys, these all are Cross Site Scripting(XSS) issues: POC1: https://www.youtube.com/w

Disclosed: 2016-09-14 12:07:34 By unkn7wn To olx
Unknown
Vulnerability Details
these are my old reports and still i have not receive any good replys, these all are Cross Site Scripting(XSS) issues: POC1: https://www.youtube.com/watch?v=zpckM4AjeWk POC2: https://www.youtube.com/watch?v=L4h_WJfIdow POC3: https://youtu.be/vWqVpPbn0AI , i am waiting for good reply... [DETAILS]: XSS(Cross Site Script)-Vulnerability: President Cross Site Scriptting Vulnerability Exist on message for ad page via ad data such as title & Desscription. Steps: 1-> open olx.com 2-> click on Submit a Free Ad 3-> now fill data in title and desscription "><img src="err" onerror="alert('President Cross Site Scriptting - XSS');"> 4-> and fill complete form then click on Submit to save ad 5-> now you will see alert box with text 'President Cross Site Scriptting - XSS' because XSS. XSS in search parameter: view-source:https://www.olx.in/all-results/q-XSS/ Persistent XSS vulnerability in OLX: https://youtu.be/vWqVpPbn0AI https://www.youtube.com/watch?v=zpckM4AjeWk https://www.youtube.com/watch?v=L4h_WJfIdow https://youtu.be/vWqVpPbn0AI
Actions
View on HackerOne
Report Stats
  • Report ID: 157889
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report