Cross-Site Scripting Stored On Rich Media
P
Pushwoosh
Submitted None
Actions:
Reported by
hussain_0x3c
Vulnerability Details
Technical details and impact analysis
**Hi Team Security Pushwoosh**
I'm Found Bug Cross-site Scripting Stored in On Rich Media .
Steps to verify
---
* . Login as **Attacker**
* . Go To **Rich Media** and Create New Media
* . Fill Name and Choose Zip Upload
* . Upload **index.zip** in **Attachments**
* . Cick Save and Enter to Media
Waiting Page to Reload Payloads ..
**XSS execute !!**
POC
---
PIC :- http://i.imgur.com/cOlh88C.png
**Testing :- Firefox**
**Regards**
@Hussain
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic