HTML injection in review content
None
J
Judge.me
Submitted None
Actions:
Reported by
0xteles
Vulnerability Details
Technical details and impact analysis
Hi Judge Security Team,
I found a HTML Injection in review parameter at the https://judgeme-pentest.myshopify.com/products/pentest and at the judge.me
###Steps
1. Go to https://judgeme-pentest.myshopify.com/products/pentest
2. Click on "Write Review"
3. fill in the fields normally.
{F1083621}
4. Now, go to your profile review in the judge.me
5. Edit your Review
6. In Review body, enter this payload: ``` <a href=https://google.com/>CLICK HERE</a>```
7. Save and go to https://judgeme-pentest.myshopify.com/products/pentest
{F1083622}
8. Boyaah.
{F1083623}
## Impact
the attacker can insert HTML codes on the page
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Command Injection - Generic