Loading HuntDB...

Stored XSS via Send crew invite

Medium
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report, the researcher was able to demonstrate a vulnerability in our Crew Invite mechanism that could have allowed an attacker to carry out a Stored XSS attack. By modifying a request in-flight and injecting unexpected characters in the Invitation message body, it was possible to escape our filters and perform the attack. To fix this, we have updated our anti-XSS efforts site-wide, and additionally ensured that we are filtering and escaping control characters and other unexpected characters on this endpoint.

Reported by fa1rlight

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored