Stored XSS via Send crew invite
Medium
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher was able to demonstrate a vulnerability in our Crew Invite mechanism that could have allowed an attacker to carry out a Stored XSS attack. By modifying a request in-flight and injecting unexpected characters in the Invitation message body, it was possible to escape our filters and perform the attack. To fix this, we have updated our anti-XSS efforts site-wide, and additionally ensured that we are filtering and escaping control characters and other unexpected characters on this endpoint.
Actions:
Reported by
fa1rlight
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored