Html Injection and Possible XSS in main nordvpn.com domain
Medium
N
Nord Security
Submitted None
Actions:
Reported by
kiriknik
Vulnerability Details
Technical details and impact analysis
## Summary:
HTML injection in main domain can allow hackers forward users to any another domain. Also, if anybody can find method to bypass cloudflare filter hackers can steak cookie with with vuln
## Steps To Reproduce:
[add details for how we can reproduce the issue]
1. Go to https://nordvpn.com/blog/?1%25%32%32%25%33%65%25%33%63%25%32%66%25%36%31%25%33%65%25%33%63%25%36%31%25%30%63href%25%33%64%25%32%32http://3232235777
2. Check, that links on the bottom of page goes to 192.168.1.1
{F692879}
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
* [attachment / reference]
## Impact
The vulnerability allow a malicious user to inject html tags and (possible) execute Javascript which could lead to steal user's session
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected