Error Page Content Spoofing or Text Injection
Low
S
Sifchain
Submitted None
Actions:
Reported by
g4urav_19
Vulnerability Details
Technical details and impact analysis
i want to report a context spoofing or text injection at api-cryptoeconomics.sifchain.finance and market-data.sifchain.finance
steps to reproduce:
1: Just browse this target on any browser
2: Target: https://api-cryptoeconomics.sifchain.finance/
3: Then add any text or content after the "/" , i added this content
4: For example: !!!ATENTION!This_server_is_on_Maintenance_please_go_to_WWW.EVIL.COM
5: Now browser reflect the content or text which you add in url.
Repeat the same process for https://market-data.sifchain.finance/
You can see also image which i had attached
F1300496
F1300495
## Impact
Fix & Mitigation:
Fix 404 error page to a new who not allow text content injection
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable