Loading HuntDB...

RXSS in ███ via S parameter

Medium
M
Mars
Submitted None

Team Summary

Official summary from Mars

A Reflected Cross-Site Scripting (RXSS) vulnerability is identified in the search functionality of the application. The vulnerability is triggered when a user manipulates the search parameter 's'. When the search statement is edited by a victim, malicious JavaScript code can be executed in their browser context. The vulnerability is discovered in the application's search feature, where user input is not properly sanitized before being reflected back to users.

Reported by mo_salah12

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected