█████ - DOM-based XSS
Medium
Vulnerability Details
Greetings,
I've discovered a DOM-based XSS at **███**
**_Proof of concept:_**
**1.** Go to https://████/█████████/home/troubleshoot.html?lang=en
**2.** In the username field, add the following code:
```
--><button/autofocus/onfocus=Function("confirm`1`")();//name="XSS
```
**3.** The javascript code is correctly executed:
██████
## Impact
With this vulnerability, an attacker can for example steal users cookies or redirect users on malicious website.
Thanks for your attention and let me know if you need anything.
Regards, Yumi
Actions
View on HackerOneReport Stats
- Report ID: 377264
- State: Closed
- Substate: resolved
- Upvotes: 3