Loading HuntDB...

Stored XSS at https://finance.owox.com/customer/accountList

Low
O
OWOX, Inc.
Submitted None

Team Summary

Official summary from OWOX, Inc.

XSS on finance.owox.com instance POC: 1) Login to zhe site 2) Go to the https://finance.owox.com/customer/accountList 3) You will be XSSed immediately. Reproduce steps: 1) Go to the https://finance.owox.com/customer/accountAdd Place in the username next payload: "><script>alert(document.cookie);</script> 3) Go to the https://finance.owox.com/customer/accountList. You will be XSSed since server not escaping quotes and <> entities.

Reported by sp1d3rs

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic