Loading HuntDB...

athome.starbucks.com - URL parameter tampering of review forms permitted possible content injection

Medium
S
Starbucks
Submitted None

Team Summary

Official summary from Starbucks

jackb898 discovered that the review forms on the informational site athome.starbucks.com was susceptible to parameter tampering possibly allowing for creation of limited custom review form content. @jackb898 — thank you for reporting the original vulnerability, the additional information and for confirming the resolution.

Reported by jackb898

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Input Validation