Loading HuntDB...

Report Design Critical Stored DOM XSS Vulnerability

Critical
I
Infogram
Submitted None
Reported by mksecurity

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
Hi Team, Another XSS vulnerability in report designer but this one is critical. **Problem Point** Report's Overview Table **Report Creation Url** https://infogram.com/app/#edit/e7b161f1-f708-48e5-bab7-de9887ae202a **Sample Data** <a href="" onmouseover="blocked:alert('HackerOne MkSecurity Dom XSS');">Click for Detail</a> **Sample URL** https://infogram.com/report-classic-1g57pr0g3xdvp01

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored