gameskinny

1 article
sort: new top best
clear filter
0 6/10
vulnerability

A stored XSS vulnerability was discovered in GameSkinny's article/post creation feature, allowing attackers to inject SVG payloads (e.g., `"><svg/onload=alert(1)>`) that execute in the browser when articles are previewed or shared with other users, potentially enabling session hijacking and cookie theft. The vulnerability was disclosed publicly after the vendor failed to respond to responsible disclosure attempts.

GameSkinny Friendly @Skeletorkeys
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details