Loading HuntDB...

Cross-Site Scripting Stored On Rich Media

P
Pushwoosh
Submitted None
Reported by hussain_0x3c

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
**Hi Team Security Pushwoosh** I'm Found Bug Cross-site Scripting Stored in On Rich Media . Steps to verify --- * . Login as **Attacker** * . Go To **Rich Media** and Create New Media * . Fill Name and Choose Zip Upload * . Upload **index.zip** in **Attachments** * . Cick Save and Enter to Media Waiting Page to Reload Payloads .. **XSS execute !!** POC --- PIC :- http://i.imgur.com/cOlh88C.png **Testing :- Firefox** **Regards** @Hussain

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic