Loading HuntDB...

[chatws25.stream.highwebmedia.com] - Reflected XSS in c parameter

Medium
C
Chaturbate
Submitted None
Reported by kazan71p

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
Hi Team, Found that `chatws25.stream.highwebmedia.com` is vulnerable to reflected XSS in `c` parameter, we can verify it with following URL, it is also a Cloudflare filter bypass: https://chatws25.stream.highwebmedia.com/ws/007/tgpraolp/htmlfile?c=███ ``` https://chatws25.stream.highwebmedia.com/ws/007/tgpraolp/htmlfile?c=███████ ``` {F350412} ## Impact One of the most common XSS attack vectors is to hijack legitimate user accounts by stealing their session cookies.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$350.00

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected