Loading HuntDB...

XSS on Report Classic

I
Infogram
Submitted None
Reported by nihadrekanym

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
hi team ... i found XSS on https://infogram.com/app/#/library #step .. 1- go to https://infogram.com/app/#/library 2- choose __Report Templates__ . 3- Use __Report Classic__ 4- click to __edit_data__ 5- payload > <img/ src=1 onerror= alert(document.cookie)> //#"><svg/onload=prompt(1)> “><script>alert(document.cookie)</script> 6-execute XSS and which you edit data XSS stared

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored