Skip to content

Commit 2b6c38b

Browse files
committed
Document reflected XSS vuln
1 parent ac454d2 commit 2b6c38b

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

README.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,3 +71,13 @@ Customer;Month;Volume
7171
Netflix;January;200,000
7272
Palo Alto;January;200,000
7373
```
74+
75+
### XSS
76+
77+
A reflected XSS vulnerability exists in the application and can be triggered using the _hidden_ `/debug` endpoint as follows:
78+
79+
```
80+
http://localhost:8080/debug?customerId=1&clientId=1&firstName=a&lastName=b&dateOfBirth=123&ssn=123&socialSecurityNum=1&tin=123&phoneNumber=5432<scriscriptpt>alert(1)</sscriptcript>
81+
```
82+
83+
It raises and alert dialogue and returns the Customer object data.

0 commit comments

Comments
 (0)