Blind stored xss in https://indeed.teamconnect.com

Disclosed by
Akrachli_Yassine
  • Engagement Indeed
  • Disclosed date almost 2 years ago
  • Reward $400
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Akrachli_Yassine

The report discusses a Blind Stored XSS vulnerability that was discovered in the https://indeed.teamconnect.com/INDEED/globalSearch.htm?r=3 website. I was able to exploit the vulnerability by injecting malicious code into a form on the website and storing it there. The form was intended for entering information about federal actions. When an administrator accessed the compromised page, the malicious code was designed to execute and capture sensitive information such as the contents of the computer screen, local storage, cookies, and other confidential data.

Activity