XSS on Report Classic
I
Infogram
Submitted None
Actions:
Reported by
nihadrekanym
Vulnerability Details
Technical details and impact analysis
hi team ...
i found XSS on https://infogram.com/app/#/library
#step
..
1- go to https://infogram.com/app/#/library
2- choose __Report Templates__ .
3- Use __Report Classic__
4- click to __edit_data__
5- payload
> <img/ src=1 onerror= alert(document.cookie)>
//#"><svg/onload=prompt(1)>
“><script>alert(document.cookie)</script>
6-execute XSS and which you edit data XSS stared
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored