Flash XSS on swfupload.swf showing at app.mavenlink.com

Disclosed: 2014-07-24 17:48:10 By panchocosil To mavenlink
Unknown
Vulnerability Details
Hello Security I like to report a XSS that affect all users. This flash XSS can be very dangerous. Vulnerable URL: https://app.mavenlink.com/flash/swfupload.swf?movieName="]);}catch(e){}if(!self.a)self.a=!alert(document.domain);// I attach image of Proof: Any problem reproducing this bug please let me know. PS: This Work with all browsers. Regards.
Actions
View on HackerOne
Report Stats
  • Report ID: 21150
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report