Reflected XSS on vimeo.com/musicstore
V
Vimeo
Submitted None
Actions:
Reported by
stefanovettorazzi
Vulnerability Details
Technical details and impact analysis
__Description__
The value of the parameter _section_ is reflected in the Javascript function `MusicStoreCommon.initialize()` without escaping, which allows to insert Javascript code.
__Proof of concept__
1. Go to https://vimeo.com/musicstore?section=%27-alert(document.domain)-%27.
2. `alert(document.domain)` is executed.
This reflected XSS is reproducible on Chrome, Safari and Firefox.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic