[www.zomato.com] Blind XSS in one of the Admin Dashboard
Z
Zomato
Submitted None
Team Summary
Official summary from Zomato
@sandeep_hodkasia identified a Blind XSS vulnerability that fired in one of our admin dashboard. #### POC - @sandeep_hodkasia added `"><script>alert(0);</script>` [XSS Hunter was used in this case] in address field while placing an order. - XSS triggered when one of our support agent viewed the order details. Thanks @sandeep_hodkasia for helping us keep @zomato secure :) Best, Prateek
Actions:
Reported by
sandeep_hodkasia
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored