Stored XSS via Post Tittle Enabling Non-Privileged User to Privileged User Exploitation on https://forums.autodesk.com/
High
A
Autodesk
Submitted None
Team Summary
Official summary from Autodesk
A stored cross-site scripting (XSS) vulnerability was found on Autodesk Forums, which could have allowed an attacker to inject malicious JavaScript code when viewed by both non-privileged and privileged users. Autodesk has fixed the vulnerability and we thank @the-white-evil for reporting this issue.
Actions:
Reported by
the-white-evil
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored