Blind Stored XSS In "Report a Problem" on www.data.gov/issue/
Medium
G
GSA Bounty
Submitted None
Actions:
Reported by
rioncool22
Vulnerability Details
Technical details and impact analysis
Step To Produce :
1. Open : https://www.data.gov/issue/
2. fill "Issue Title" and "Description" With XSSHunter Payload
3. XSS Fired In https://labs.data.gov/crm/admin/report/662445
## Impact
Can steal admin cookies
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$300.00
Submitted
Weakness
Cross-site Scripting (XSS) - Stored