Loading HuntDB...

RXSS on ████ via q parameter

Low
M
Mars
Submitted None

Team Summary

Official summary from Mars

A reflected Cross-Site Scripting (XSS) vulnerability is identified on the █████████ website at the search endpoint. The vulnerability is present in the 'q' parameter of the search functionality, where user-supplied input is reflected back to the page without proper sanitization or encoding. This allows malicious JavaScript code to be executed in the context of other users' browsers when they visit a specially crafted URL.

Reported by mo_salah12

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected