[ CVE-2018-1000129 ] RXSS At `https://███████` via the URI

Disclosed: 2024-12-18 19:43:56 By todayisnew- To deptofdefense
Medium
Vulnerability Details
Hi `DOD` Team, ## System Host(s) ████████ CVE Numbers: * # CVE-2018-1000129 # POC: * https://█████%3Csvg%20onload=alert%28'1337'%29%3E?mimeType=text/html * https://██████████%3Csvg%20onload=alert%28document.domain%29%3E?mimeType=text/html * https://████████%3Csvg%20onload=alert%28document.cookie%29%3E?mimeType=text/html * ████ ## Impact Attackers can execute scripts in a victim’s browser to steal the user's cookies, hijack user sessions, deface websites, insert hostile content, redirect users, hijack the user’s browser using malware, etc... Thanks.
Actions
View on HackerOne
Report Stats
  • Report ID: 2778412
  • State: Closed
  • Substate: resolved
Share this report