athome.starbucks.com - URL parameter tampering of review forms permitted possible content injection
Medium
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
jackb898 discovered that the review forms on the informational site athome.starbucks.com was susceptible to parameter tampering possibly allowing for creation of limited custom review form content. @jackb898 — thank you for reporting the original vulnerability, the additional information and for confirming the resolution.
Actions:
Reported by
jackb898
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Input Validation