XSS and Open Redirect on https://jobs.dubizzle.com/

Disclosed: 2016-10-20 14:24:19 By mefkan To olx
High
Vulnerability Details
Hi, I found an interesting vulnerability.With this one we can redirect someone to a malicious site,or we can trigger XSS. STEPS TO REPRODUCE --------------------- 1-Go to that link https://jobs.dubizzle.com/en/pricing/?return=javascript:prompt(31) 2-Click the "Continue placing your ad" button. 3-XSS will execute. For Open Redirect,we can use these link https://jobs.dubizzle.com/en/pricing/?return=http://example.com TESTING --------------------- Tested and confirmed Chrome's and Firefox's latest versions.
Actions
View on HackerOne
Report Stats
  • Report ID: 167107
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report