Loading HuntDB...

Dom based xss on https://www.rockstargames.com/ via `returnUrl` parameter

Medium
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report, the researcher identified a DOM-Based Cross-Site Scripting vulnerability in the Videos section of the GTAOnline site that appeared to only be exploitable on non-English versions of the site, such as /br/. The root cause appeared to lay in the ReturnUrl parameter in the logout function. Thanks to this report we were able to resolve this issue.

Reported by netfuzzer

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - DOM