reflected XSS on panther.com

Disclosed: 2022-07-23 05:19:50 By ibrahimatix0x01 To panther_labs
Medium
Vulnerability Details
## Summary: When visiting runpanther.io I got redirected to panther.com and the application failed to sanitise user's input resulting into HTML injection and possible XSS. ## Steps To Reproduce: {F1774502} 1. Go to https://panther.com/search/Users%3Ch1%3EHello,%20I%20am%3C/h1%3E%3Cfont%20color=red%3E%20Ibrahimatix0x01%3C/font%3E 1. You will notice that HTML codes in the search form are executed by the browser. ## Supporting Material/References: {F1774497} ## Impact The vulnerability allow a malicious user to inject html tags and could possibly execute Javascript (if WAF is successfully bypassed)which could lead to steal user's session
Actions
View on HackerOne
Report Stats
  • Report ID: 1601140
  • State: Closed
  • Substate: resolved
  • Upvotes: 62
Share this report