Reflective XSS vulnerability on a DoD website
Low
U
U.S. Dept Of Defense
Submitted None
Team Summary
Official summary from U.S. Dept Of Defense
A cross-site scripting vulnerability was found on a Department of Defense website which may trick a web user into executing a malicious script, potentially revealing a user's web session information or modify web content. Multiple researchers were able to demonstrate this vulnerability by crafting a specially formatted URL. Thanks @fantam and @rashedhasan007!
Actions:
Reported by
fantam1
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic