vulnerability-writeup

2 articles
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability where unsanitized URL parameters (refclickid) are stored in cookies and later reflected in JSON responses within script tags, allowing arbitrary JavaScript execution on any page visit. The vulnerability relies on the application trusting cookie values without sanitization when inserting them into script contexts.

Arbaz Hussain HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 6/10
vulnerability

Stored XSS vulnerability discovered in RunKeeper's user profile name field that reflects malicious payloads to all users viewing the profile, combined with site-wide CSRF issues enabling creation of an XSS worm that forces victims to follow attacker accounts. The vulnerability was originally reported in 2013, but a bypass was found in 2015.

RunKeeper ASICS Mohamed A. Baset David Sopas Seekurity Norwegian Consumer Council Jason Jacobs
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details