Loading HuntDB...

Stored XSS via Post Tittle Enabling Non-Privileged User to Privileged User Exploitation on https://forums.autodesk.com/

High
A
Autodesk
Submitted None

Team Summary

Official summary from Autodesk

A stored cross-site scripting (XSS) vulnerability was found on Autodesk Forums, which could have allowed an attacker to inject malicious JavaScript code when viewed by both non-privileged and privileged users. Autodesk has fixed the vulnerability and we thank @the-white-evil for reporting this issue.

Reported by the-white-evil

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored