[website] Script injection in newsletter signup https://brave.com/brave_youth_program_signup.html
Medium
B
Brave Software
Submitted None
Actions:
Reported by
cmd-0_0
Vulnerability Details
Technical details and impact analysis
go to https://brave.com/brave_youth_program_signup.html
click become an ambasador
insert malicious payloads in the fields <a href='evil,com'>YOU JUST WON 1m$ </a>
you will receive a mail like in the image attached.
You can send phising emails and do other bad stuff.
If you need more details i'm here.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Command Injection - Generic