Loading HuntDB...

Google Authenticator - Cross Site Scripting

I
Ian Dunn
Submitted None
Reported by iamsha4yan

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hello #Vulnerable File: : `/views/token-prompt.php` #Vulnerable Link : `15` `<input type="hidden" name="gapup_login_nonce" value="<?php echo esc_attr( $_REQUEST['gapup_login_nonce'] ) ?>" />` # Vulnerable Code: `<?php echo esc_attr( $_REQUEST['gapup_login_nonce'] ) ?>` Good Luck/

Report Details

Additional information and metadata

State

Closed

Substate

Not-Applicable

Submitted

Weakness

Cross-site Scripting (XSS) - Generic