Loading HuntDB...

Blind Stored XSS In "Report a Problem" on www.data.gov/issue/

Medium
G
GSA Bounty
Submitted None
Reported by rioncool22

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
Step To Produce : 1. Open : https://www.data.gov/issue/ 2. fill "Issue Title" and "Description" With XSSHunter Payload 3. XSS Fired In https://labs.data.gov/crm/admin/report/662445 ## Impact Can steal admin cookies

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$300.00

Submitted

Weakness

Cross-site Scripting (XSS) - Stored