Self XSS

Disclosed: 2024-07-19 14:28:19 By 0xtrav To deptofdefense
Medium
Vulnerability Details
**Description:** I Have found a Self XSS in ```https://█████████/ords/f?p=1001:2::::::``` + POC 1. Go To ```https://████████/``` 2. Go to Search Function 3. Then Insert a Normal XSS payload like ==<script>alert(document.cookie)</script>==The XSS will fireup ████ ## Impact XSS Attacks ## System Host(s) ██████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce 1. Go To ```https://█████████/``` 2. Go to Search Function 3. Then Insert a Normal XSS payload like ==<script>alert(document.cookie)</script>==The XSS will fireup ## Suggested Mitigation/Remediation Actions Remediation By Filtering the user input in search function specially in ==f02 paramter==
Actions
View on HackerOne
Report Stats
  • Report ID: 2521186
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report