Loading HuntDB...

Unfiltered input allows for XSS in "Playtime Item Grants" fields

Medium
V
Valve
Submitted None

Team Summary

Official summary from Valve

Enter ">test in any of the 3 fields, save it and reload the page. Impact Stored XSS, could possibly break some internal features too as the stored value is not an integer. The hacker selected the Cross-site Scripting (XSS) - Stored weakness. This vulnerability type requires contextual information from the hacker. They provided the following answers: URL https://partner.steamgames.com/apps/inventoryservice/[xxx]

Reported by xpaw

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored