Loading HuntDB...

XSS Reflected on reddit.com via url path

High
R
Reddit
Submitted None
Reported by criptex

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
Hi I found a XSS-R To reproduce the issue please click the poc link and then press the "verify email" button PoC: https://www.reddit.com/verification/asd',%20alert(document.location),%20%27 ## Impact With the help of XSS an attacker can steal your cookies, in many cases steal sessions, download malware onto your system and send a custom request. Users can be socially engineered by the attacker by redirecting them from the real website to a fake one and there are many more attack scenarios that an expert attacker can perform with XSS. It is also possible to inject html thus modifying the original page

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected