
Summary: When applying for a Supporter/Moderator job at recruit.innogames.de the drop-down field "Position" is vulnerable to a stored XSS as the content is not validated. Description: Steps To Reproduce: Visit https://recruit.innogames.de/staemme/de/index/page/show/apply Fill out all required fields. Intercept request when pushing the send button "Bewerbung abschicken" Change value of "position" field to a short Javascript payload. The length is limited by the backend. I used a short domain and omitted the protocol part of the url to make it fit. Eg. "> Wait for the confirmation email and the status page should execute your script. Impact: Perform arbitrary requests on the behalf of other users Read any data the attacked user has access to on the page Unknown impact on the backend as the application was not reviewed in the last week but I guess there will be some place the script will execute ;) Supporting Material/References: PoC: https://recruit.innogames.de/staemme/de/index/show/id/60420f7765bb9b4ffaac0ddc09f9003e5b9a4d2d Impact Perform arbitrary requests on the behalf of other users Read any data the attacked user has access...
SOCIAL SHARE CARD GENERATOR