[chatws25.stream.highwebmedia.com] - Reflected XSS in c parameter
Medium
C
Chaturbate
Submitted None
Actions:
Reported by
kazan71p
Vulnerability Details
Technical details and impact analysis
Hi Team,
Found that `chatws25.stream.highwebmedia.com` is vulnerable to reflected XSS in `c` parameter, we can verify it with following URL, it is also a Cloudflare filter bypass:
https://chatws25.stream.highwebmedia.com/ws/007/tgpraolp/htmlfile?c=███
```
https://chatws25.stream.highwebmedia.com/ws/007/tgpraolp/htmlfile?c=███████
```
{F350412}
## Impact
One of the most common XSS attack vectors is to hijack legitimate user accounts by stealing their session cookies.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$350.00
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected