Report Design Critical Stored DOM XSS Vulnerability
Critical
I
Infogram
Submitted None
Actions:
Reported by
mksecurity
Vulnerability Details
Technical details and impact analysis
Hi Team,
Another XSS vulnerability in report designer but this one is critical.
**Problem Point**
Report's Overview Table
**Report Creation Url**
https://infogram.com/app/#edit/e7b161f1-f708-48e5-bab7-de9887ae202a
**Sample Data**
<a href="" onmouseover="blocked:alert('HackerOne MkSecurity Dom XSS');">Click for Detail</a>
**Sample URL**
https://infogram.com/report-classic-1g57pr0g3xdvp01
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored