Stored XSS at https://finance.owox.com/customer/accountList
Low
O
OWOX, Inc.
Submitted None
Team Summary
Official summary from OWOX, Inc.
XSS on finance.owox.com instance POC: 1) Login to zhe site 2) Go to the https://finance.owox.com/customer/accountList 3) You will be XSSed immediately. Reproduce steps: 1) Go to the https://finance.owox.com/customer/accountAdd Place in the username next payload: "><script>alert(document.cookie);</script> 3) Go to the https://finance.owox.com/customer/accountList. You will be XSSed since server not escaping quotes and <> entities.
Actions:
Reported by
sp1d3rs
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic