Loading HuntDB...

HTML injection in review content

None
J
Judge.me
Submitted None
Reported by 0xteles

Vulnerability Details

Technical details and impact analysis

Command Injection - Generic
Hi Judge Security Team, I found a HTML Injection in review parameter at the https://judgeme-pentest.myshopify.com/products/pentest and at the judge.me ###Steps 1. Go to https://judgeme-pentest.myshopify.com/products/pentest 2. Click on "Write Review" 3. fill in the fields normally. {F1083621} 4. Now, go to your profile review in the judge.me 5. Edit your Review 6. In Review body, enter this payload: ``` <a href=https://google.com/>CLICK HERE</a>``` 7. Save and go to https://judgeme-pentest.myshopify.com/products/pentest {F1083622} 8. Boyaah. {F1083623} ## Impact the attacker can insert HTML codes on the page

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Command Injection - Generic