8000 [Security] Cross Site Scripting in the operation name value · Issue #1755 · mitre/caldera · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
[Security] Cross Site Scripting in the operation name value #1755
Closed
@Dfte

Description

@Dfte

Hello,

I was playing with your framework when i came across a XSS in the Operation Name box:
payload: <script>alert()</script>

image

I have no idea if you guys are interested in that type of vulnerability but i thought it would be nice to inform you anyway :) !

Have a good day,
Defte

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0