search-parameter

2 articles
sort: new top best
clear filter
0 3/10

Researcher discovered a reflected XSS vulnerability in Oracle NetSuite's search functionality that could be triggered via accesskey attribute combined with onclick handler in URL parameters, requiring victim interaction (Alt+Shift+X keyboard shortcut).

Oracle NetSuite Circle Ninja
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details
0 3/10
vulnerability

Reflected XSS vulnerability discovered in ASUS's press subdomain (press.asus.com/search) via unsanitized search parameter, exploited with a basic script injection payload and resolved within 13 days of responsible disclosure.

ASUS Thejus Krishnan press.asus.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details