Loading HuntDB...

Reflected xss in https://sh.reddit.com

High
R
Reddit
Submitted None
Reported by abhiramsita

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
## Summary: Reflected cross-site scripting (or XSS) arises when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe way. ## Impact: attacker can execute malicious java script and steal cookies ## Steps To Reproduce: [add details for how we can reproduce the issue] Hi team , Navigate to below url scroll to page end find a option see more Move mouse over there and observe the execution of javascript ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact attacker can execute malicious java script and steal cookies

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$5000.00

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected