Loading HuntDB...

Html Injection and Possible XSS in main nordvpn.com domain

Medium
N
Nord Security
Submitted None
Reported by kiriknik

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
## Summary: HTML injection in main domain can allow hackers forward users to any another domain. Also, if anybody can find method to bypass cloudflare filter hackers can steak cookie with with vuln ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. Go to https://nordvpn.com/blog/?1%25%32%32%25%33%65%25%33%63%25%32%66%25%36%31%25%33%65%25%33%63%25%36%31%25%30%63href%25%33%64%25%32%32http://3232235777 2. Check, that links on the bottom of page goes to 192.168.1.1 {F692879} ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact The vulnerability allow a malicious user to inject html tags and (possible) execute Javascript which could lead to steal user's session

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected