html injection in [https://edoiu.doi.gov/login/signup.php]

Disclosed by
CryptoKnight028's avatar
CryptoKnight028
Summary by CryptoKnight028

HTML injection via confirmed account email

Report details
  • Submitted

  • Target Location

    *.doi.gov
  • Target category

    Web App

  • VRT

    Server-Side Injection > Content Spoofing > Email HTML Injection
  • Priority

    P4
  • Bug URL
    https://edoiu.doi.gov/
  • Description

    Hi team,
    I found html injection on edoiu account request approved email .

    Steps_to_produce :
    1) Go to page (https://edoiu.doi.gov/login/signup.php)
    2) Type html payload in "username" field
    <h1>USERNAME</h1> or <a href="www.evil.com">
    3) Then click on request account
    4) After 1-2 days ,account approved mail will come in that you can see html code is executed in mail .

    Impact :
    1) This vulnerability can lead to the reformatting/editing of emails from an official email address, which can be used in targeted phishing attacks.
    2) This could lead to users being tricked into giving logins away to malicious attackers.

    Image is attached as poc .

Activity
  1. DOI_RPI’s avatar
    DOI_RPI Customer published the disclosure report

    ()

  2. CryptoKnight028’s avatar
    CryptoKnight028 requested disclosure

    ()

  3. DOI_RPI’s avatar
    DOI_RPI Customer sent a message

    ()

  4. DOI_RPI’s avatar
    DOI_RPI Customer changed the state to Resolved

    ()

  5. DOI_RPI’s avatar
    DOI_RPI Customer sent a message

    ()

  6. IOS_DOI_KM’s avatar
    IOS_DOI_KM Customer changed the state to Unresolved

    ()

  7. IOS_DOI_KM’s avatar
    IOS_DOI_KM Customer changed the state to Triaged

    ()

  8. IOS_DOI_KM’s avatar
    IOS_DOI_KM Customer changed the state to Unresolved

    ()

  9. chickenJoe’s avatarbugcrowd logo
    chickenJoe sent a message

    ()

  10. chickenJoe’s avatarbugcrowd logo
    chickenJoe changed the state to Triaged

    ()

  11. chickenJoe’s avatarbugcrowd logo
    chickenJoe updated the submission

    ()

  12. CryptoKnight028’s avatar
    CryptoKnight028 created the submission

    ()