Loading HuntDB...

RXSS at image.hackerone.live via the `url` parameter

Low
H
HackerOne
Submitted None
Reported by todayisnew

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
good day https://image.hackerone.live:8443/;/;/resource/md/get/url?url=http://oast.pro is allowing full read ssrf wirh permission can try for aws creds. -Eric ## Impact full read ssrf

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.01

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected