Loading HuntDB...

DOM based XSS on /GTAOnline/tw/starterpack/

Medium
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report the researcher identified a DOM-based XSS vulnerability impacting localized versions of the `https://www.rockstargames.com/GTAOnline/` site in varying locations. This attack also took advantage of an Open Redirect vulnerability on another part of the site to demonstrate how an attacker could use this to exfiltrate sensitive tokens via the Referer header. The Open Redirect was fixed in another report, and the XSS was addressed in this report. This behavior is no longer exploitable.

Reported by netfuzzer

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - DOM