RXSS on TikTok endpoints
Medium
T
TikTok
Submitted None
Team Summary
Official summary from TikTok
A Cross-Site Scripting (XSS) vulnerability was found on two TikTok incentive endpoints, due to the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload could be injected into the affected endpoint causing it to be executed within the context of a user's browser. We thank @ashrafabdelrazik for reporting this to our team.
Actions:
Reported by
ashrafabdelrazik
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected