[careers.informatica.com] XSS on "isJTN"

Disclosed: 2017-04-07 16:29:46 By huntertxt To informatica
High
Vulnerability Details
hi , i found XSS bug on parameter "isJTN=" at careers.informatica.com give you ability to run java script code tested on firefox 50.0.2 also on old version of google chrome in the last version , but if try this bug in chrome last version you will got a source code displayed on page with out run cuz security protected stop XSS code * POC used payload : </ScrIpt><SCRIPT>+alert("X");</SCRIPT> https://careers.informatica.com/apply?applySource=Quick%20Apply&isJTN=</ScrIpt><SCRIPT>+alert("X");</SCRIPT>true&isQuickApply=false are this eligible for swag !? cheer
Actions
View on HackerOne
Report Stats
  • Report ID: 190020
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report