Stored xss

Disclosed: 2014-09-27 08:25:07 By detroitsmash To x
Unknown
Vulnerability Details
Hi! There's a stored xss on ads.twitter.com under "Add New App" section at https://ads.twitter.com/accounts/18ce53wsl3g/campaigns/new_objective/app_installs. There's a option to add android application by Google play app id, so i searched for a app on play store with name " "><img src=x onerror=alert(1)>" " and then i got this app https://play.google.com/store/apps/details?id=com.rssappmaker.athe319. So to reproduce this copy paste the app id "com.rssappmaker.athe319" in that box and then click on "add app" button. After that this xss will be triggered. See the attached image poc.png Tested in latest version of chrome. Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 27846
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report