XSS on Bugcrowd and so many other website's main Domain
Hi all,
This is my first Blog post. I recently found Reflected Cross Site Scripting(XSS) vulnerability on Bugcrowd main domain which had huge impact.
Secret Parameter:
I was able to identify one secret parameter which was getting used by the server to respond differently and gave up error page showing `unable to find page 404 in locale <my input>`. This was pretty much atleast XSS and Yes!
Here is the POC video:
This didn't only work on 404 page but also on the homepage for ex: `https://bugcrowd.com?locale=xss`. However this parameter didn't seem to do anything else, so I immediately reported to Bugcrowd. When I woke up in the morning, I came to know that this bug was rather in Locomotive CMS, bugcrowd worked around showing that page at router level to mitigate the impact .
Knowing this I immediately checked out Locomotive CMS and so was their website vulnerable.
So I went dorking for other websites using Locomotive CMS and I have so many POP UPS! but I can't show them because they are still vulnerable.
If your application is using Locomotive CMS, chances are you are also vulnerable, but don't worry If you find that you have this vulnerability, I believe there is a patch out there. Contact Locomotive CMS for more information.
This had huge impact as all the submission data and other important information is hosted on main domain which means one click and few seconds of javascript processing will steal all the data from the user and take actions on behalf of users(CSRF).
After few days Locomotive fixed the bug and allowed disclosure. You can easily find some locomotive CMS application to test this out.
Bugcrowd rewarded $600 for this, I didn't agree with the reward amount but it was really nice to see the Quick Fix.
Got Thoughts? Tweet me here @v0sx9b ! Thanks for reading :)
Great one, congrats! :-)
ReplyDeleteThank you! :))
Deletegood one , may i know what was your way or how did you find the parameter ?locale=
ReplyDeletejust some manual fuzzing!
Deleteawesome write up! congrats! any dork for search locomotive CMS ? thanks
ReplyDeletewow!
ReplyDeleteSands Casino NJ Review | Online & Mobile Gambling
ReplyDeleteSands Casino NJ review: Slots, Table Games, Poker, Roulette, Online, or mobile, you can play 우리 계열 샌즈 카지노 a variety of slot and table games.
0turgeodendwa_Manchester Jan Roberts https://wakelet.com/wake/0HNsBbTnwTzmcOvRUeD2z
ReplyDeleteeninjsonle
lustvisQnista_1990 Nancy Hall click here
ReplyDeleteclick
click
https://colab.research.google.com/drive/1RpB4r8qICWlAv3g0SxoUpljSHA8DOKdh
healthholrepu
gisrenunna_1998 Jayson Sandell Adobe Media Encoder
ReplyDeleteBandicam
Recover My Files
fthehmuncakal
Great and I have a dandy offer you: What Renos Add Value house remodeling services
ReplyDelete