HTML Injection with XSS possible

Disclosed: 2021-04-29 21:15:42 By malek To imgur
Medium
Vulnerability Details
Hi, I found HTML Injection on imgur.com Description: I couldn't get xss but i was able to include videos on my profile and also i was able to redirect users to malicious websites POC (HTML injection): go to https://12test.imgur.com (you don't need to login) and you will see external videos and you will see image click on it and you will redirect to http://evil.com, note that this test page attacker page could be more normal to user, remeber that it's stored so it will show up when any user viste profile Suggested fix: Sanitize all input fields on this page. ## Impact attacker could redirect users and then execute xss and control them easily, also could include his videos to get views
Actions
View on HackerOne
Report Stats
  • Report ID: 381553
  • State: Closed
  • Substate: resolved
  • Upvotes: 56
Share this report