fitness-tracking

1 article
sort: new top best
clear filter
0 6/10
vulnerability

Stored XSS vulnerability discovered in RunKeeper's user profile name field that reflects malicious payloads to all users viewing the profile, combined with site-wide CSRF issues enabling creation of an XSS worm that forces victims to follow attacker accounts. The vulnerability was originally reported in 2013, but a bypass was found in 2015.

RunKeeper ASICS Mohamed A. Baset David Sopas Seekurity Norwegian Consumer Council Jason Jacobs
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details