simplerisk

1 article
sort: new top best
clear filter
0 5/10

CVE-2017-10711 is a reflected XSS vulnerability in SimpleRisk's password reset form where the 'user' parameter is echoed directly without sanitization, allowing attackers to execute arbitrary JavaScript and steal session cookies or hijack user sessions via CSRF.

CVE-2017-10711 SimpleRisk Mohamed A. Baset reset.php
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details