XSS on Vimeo

Disclosed: 2015-01-29 00:16:26 By niyaax To vimeo
Unknown
Vulnerability Details
Poc video: XSS on Vimeo: http://youtu.be/w5QgEEcMARY 1. Go to https://vimeo.com/settings/profile 2. Add a link with the payload on URL: javascript:alert(document.domain+"http://") 3. Click the link and payload will execute. Thanks @niyaax
Actions
View on HackerOne
Report Stats
  • Report ID: 45484
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report