Google Authenticator - Cross Site Scripting
I
Ian Dunn
Submitted None
Actions:
Reported by
iamsha4yan
Vulnerability Details
Technical details and impact analysis
Hello
#Vulnerable File: :
`/views/token-prompt.php`
#Vulnerable Link :
`15`
`<input type="hidden" name="gapup_login_nonce" value="<?php echo esc_attr( $_REQUEST['gapup_login_nonce'] ) ?>" />`
# Vulnerable Code:
`<?php echo esc_attr( $_REQUEST['gapup_login_nonce'] ) ?>`
Good Luck/
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Cross-site Scripting (XSS) - Generic