Html injection in event Description

Disclosed: 2024-01-29 04:50:05 By khaledx To linkedin
Low
Vulnerability Details
#Hi team there is Html injection when user add Description to event when public user search for published event #Step's * login to https://www.linkedin.com/groups/ * create event mark it as Public add <a href="https://malicious-site.com">Click me!</a> as Description {F2785963} * save change now navigate to ==Search== enter your event name * when ==result== show up html code get executed in the Description {F2785962} POC:F2785976 ## Impact attacker able to run html code
Actions
View on HackerOne
Report Stats
  • Report ID: 2215418
  • State: Closed
  • Substate: resolved
  • Upvotes: 50
Share this report