Reflected xss in https://sh.reddit.com
High
R
Reddit
Submitted None
Actions:
Reported by
abhiramsita
Vulnerability Details
Technical details and impact analysis
## Summary:
Reflected cross-site scripting (or XSS) arises when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe way.
## Impact:
attacker can execute malicious java script and steal cookies
## Steps To Reproduce:
[add details for how we can reproduce the issue]
Hi team ,
Navigate to below url
scroll to page end find a option see more
Move mouse over there and observe the execution of javascript
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
* [attachment / reference]
## Impact
attacker can execute malicious java script and steal cookies
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$5000.00
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected