RXSS in ███ via S parameter
Medium
M
Mars
Submitted None
Team Summary
Official summary from Mars
A Reflected Cross-Site Scripting (RXSS) vulnerability is identified in the search functionality of the application. The vulnerability is triggered when a user manipulates the search parameter 's'. When the search statement is edited by a victim, malicious JavaScript code can be executed in their browser context. The vulnerability is discovered in the application's search feature, where user input is not properly sanitized before being reflected back to users.
Actions:
Reported by
mo_salah12
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected