Loading HuntDB...

RXSS on ████ via configUrl parameter

Low
M
Mars
Submitted None

Team Summary

Official summary from Mars

A Reflected Cross-Site Scripting (RXSS) vulnerability is reported on the Swagger UI page of the Royal Canin eVet API. The vulnerability is identified in the configUrl parameter of the URL █████████. This security flaw allows an attacker to inject malicious scripts into the web page, which are then executed in the context of other users' browsers when they visit the compromised page.

Reported by kh4rish34v3n

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected