Loading HuntDB...

Reflected XSS on error page on https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action

Medium
L
Lab45
Submitted None
Reported by meryem0x

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
Hi :) In https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action `bookmarkPageId` parameter expects a number value. If you add XSS payload instead of number, an error page displays with XSS. PoC `https://apps.topcoder.com/wiki/plugins/socialbookmarking/updatebookmark.action?bookmarkPageId="><img src=x onerror=alert(document.domain)>` {F816846} ## Impact XSS can use to steal cookies or to run arbitrary code on victim's browser.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected