Post Based Reflected XSS on https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action

Disclosed: 2020-05-12 13:40:05 By meryem0x To lab45
Medium
Vulnerability Details
## Summary: Hi :) A post based reflected XSS occurs when creating bookmarks. ## Steps To Reproduce: `Title` and `Labels` parameters are vulnerable to XSS on https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action. This form uses POST request so i added HTML file below. When someone opens this html file, or we can add it into our website, XSS will execute. {F816815} {F816816} ## Impact XSS can use to steal cookies or to run arbitrary code on victim's browser.
Actions
View on HackerOne
Report Stats
  • Report ID: 866837
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report