Loading HuntDB...

[www.zomato.com] Blind XSS in one of the Admin Dashboard

Z
Zomato
Submitted None

Team Summary

Official summary from Zomato

@sandeep_hodkasia identified a Blind XSS vulnerability that fired in one of our admin dashboard. #### POC - @sandeep_hodkasia added `"><script>alert(0);</script>` [XSS Hunter was used in this case] in address field while placing an order. - XSS triggered when one of our support agent viewed the order details. Thanks @sandeep_hodkasia for helping us keep @zomato secure :) Best, Prateek

Reported by sandeep_hodkasia

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored