Loading HuntDB...

XSS on about:tbupdate

T
Tor
Submitted None
Reported by qab

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
Hello, It appears that there is an XSS vulnerability on the about:tbupdate page. Steps to reproduce: 1. Visit: about:tbupdate?blocked:alert(1) 2. Click on 'visit our website' Because the page is a privileged one (given it cannot be opened from a normal web page) this XSS may lead to a more severe issue. I will post a reply if I find a way to to do either of two things, first being finding a way to open privileged about: pages from normal content and secondly, I will check to see if there are any privileged javascript functions I could execute to achieve a bigger issue. Thank you

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected