Loading HuntDB...

Stored XSS on www.starbucks.com.sg/careers/career-center/career-landing-*

Medium
S
Starbucks
Submitted None
Reported by 13ern

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
**Summary:** While enumeration of the webpage for Starbucks I observed the following pages. https://www.starbucks.com.sg/careers/career-center/career-landing-5? The webpage have been highly spam by automated scanners or malicious attack. By clicking on any of the pages it would redirect the user to a wordpress website ``` <a href="https://obatkebaskesemutan.wordpress.com/" rel="dofollow noopener" style="z-index:9999999999999999;oncontextmenu:return false;onkeydown:return false;onmousedown:return false;position:fixed;top:0px !important;left:0px;width:100%;height:100%;color:transparent !important;display:block;text-align:center;font-size:0px;background-color:transparent;background-position:center;background-repeat:no-repeat;background-size:cover;" target="_blank" title="Obat Herbal">Obat Kebas</a> ``` The owner of the following wordpress pages could manipulate user into redirecting to a Starbucks page for a job offer and an user by clicking on the webpage would redirect to a website of its choosing. {F439338} {F439340} * List any recommendations for bug fix Remove the pages from Starbucks webpage. ## Impact The owner of the following wordpress pages could manipulate user into redirecting to a Starbucks page for a job offer and an user by clicking on the webpage would redirect to a website of its choosing.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored