Unfiltered input allows for XSS in "Playtime Item Grants" fields
Medium
V
Valve
Submitted None
Team Summary
Official summary from Valve
Enter ">test in any of the 3 fields, save it and reload the page. Impact Stored XSS, could possibly break some internal features too as the stored value is not an integer. The hacker selected the Cross-site Scripting (XSS) - Stored weakness. This vulnerability type requires contextual information from the hacker. They provided the following answers: URL https://partner.steamgames.com/apps/inventoryservice/[xxx]
Actions:
Reported by
xpaw
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored