Alexander Fuchs, A German Security Researcher Discover Persistent XSS Vulnerability in Official website of White House. He said "The
petition system is vulnerable. Every Petition i start or join will
execute my code. I could join all petitions and my code will be executed
on all users who visit the petition system."The XSS Demo is here: https://wwws.whitehouse.gov/petitions/!/petition/security/WxgwM7DS
Advisory: http://vulnerability-lab.com/get_content.php?id=308
No comments:
Post a Comment