Reflected XSS | Bug Bounty
Glad You're Here!
Lets Unlock the secrets of Reflected XSS with our expert guides
Hacking Aspirants, I am System.Exit
What is cross-site scripting (XSS)?
Cross-site scripting (also known as XSS) is a web security vulnerability that allows an attacker to compromise the interactions that users have with a vulnerable application. It allows an attacker to circumvent the same origin policy, which is designed to segregate different websites from each other. Cross-site scripting vulnerabilities normally allow an attacker to masquerade as a victim user, to carry out any actions that the user is able to perform, and to access any of the user's data. If the victim user has privileged access within the application, then the attacker might be able to gain full control over all of the application's functionality and data.
Summary:
When visiting runpanther.io I got redirected to panther.com and the application failed to sanitise user's input resulting into HTML injection and possible XSS.
Steps To Reproduce:
1. Go to [https://panther.com/search/Users%3Ch1%3EHello,%20I%20am%3C/h1%3E %3Cfont%20color=red%3E%20Ibrahimatix0x01%3C/font%3E](https://panther.com/search/Users%3Ch1%3EHello,%20I%20am%3C/h1%3E%3Cfont%20color=red%3E%20Ibrahimatix0x01%3C/font%3E)
2. You will notice that HTML codes in the search form are executed by the browser.
Comments
Post a Comment