Reflected XSS in https://www.█████/

Disclosed: 2020-09-29 20:33:43 By nirajgautamit To deptofdefense
Medium
Vulnerability Details
Hello Security Team, I would like to report the XSS vulnerability on your system. Steps To Reproduce: Visit the following POC link and move your mouse allover index page: https://www.████/(Z(%22onmouseover=alert%60%60%20%22))/████████/█████.aspx 1. Tested on firefox browser: ███████ 2.Tested on google chrome browser: █████████ ## Impact An XSS attack allows an attacker to execute arbitrary JavaScript in the context of the attacked website and the attacked user. This can be abused to steal session cookies, perform requests in the name of the victim, or for phishing attacks.
Actions
View on HackerOne
Report Stats
  • Report ID: 950700
  • State: Closed
  • Substate: resolved
  • Upvotes: 23
Share this report