RXSS on ████ via configUrl parameter
Low
M
Mars
Submitted None
Team Summary
Official summary from Mars
A Reflected Cross-Site Scripting (RXSS) vulnerability is reported on the Swagger UI page of the Royal Canin eVet API. The vulnerability is identified in the configUrl parameter of the URL █████████. This security flaw allows an attacker to inject malicious scripts into the web page, which are then executed in the context of other users' browsers when they visit the compromised page.
Actions:
Reported by
kh4rish34v3n
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected