Loading HuntDB...

Reflected XSS on vimeo.com/musicstore

V
Vimeo
Submitted None

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
__Description__ The value of the parameter _section_ is reflected in the Javascript function `MusicStoreCommon.initialize()` without escaping, which allows to insert Javascript code. __Proof of concept__ 1. Go to https://vimeo.com/musicstore?section=%27-alert(document.domain)-%27. 2. `alert(document.domain)` is executed. This reflected XSS is reproducible on Chrome, Safari and Firefox.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic