cross site scripting in : mtn.bj
High
M
MTN Group
Submitted None
Actions:
Reported by
alimanshester
Vulnerability Details
Technical details and impact analysis
## Summary:
Xss vulnerability in mtn.bj in file name
## Steps To Reproduce:
1.Go to :
https://www.mtn.bj/business/ressources/formulaires/plan-de-localisation-de-compte/?next=https://www.mtn.bj/business/ressources/formulaires/formulaire-de-souscription/
2 - fill all inputs with any data
3 - in file upload upload a file with payload file name such as : "><img src=x onerror=alert(document.cookie);.jpg
4-the payload will executed in the page .
## Supporting Material/References:
1 - video showing poc
2 - screen shot
## Impact
execute malicious java script in user browser
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected