Store XSS
High
S
Slack
Submitted None
Actions:
Reported by
imran_hadid
Vulnerability Details
Technical details and impact analysis
Hello Team.
I found a Store XSS. Where the company name is the vulnerable to XSS. If you give this below XSS script as Company name, you will get the XSS pop up after the login in message option where it'll randomly generated at the message room.
“><IMG SRC=x onerror=blocked:alert("XSS-by-Imran")>
Here is the POC:
https://youtu.be/dqrH2WhIgtk
Thanks
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic