HackerOne Disclosed Reports - 2025-03-21

0 Replies, 290 Views

Logo
Medium
resolved

Cache Poisoning Allows Zero Interaction Store XSS


Bug reported by Sam Ark was disclosed at March 22, 2025, 12:35 pm   |   Cross-site Scripting (XSS) - Stored

The vulnerability allowed an attacker to perform a cache poisoning attack, which resulted in a zero-interaction stored cross-site scripting (XSS) vulnerability on the Trendyol website. The attack was achieved by modifying the User-Agent header and adding a malicious parameter to the URL, which was then cached by the server and executed when visited by a victim.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-03-21 - by hashXploiter - 03-22-2025, 07:00 PM



Users browsing this thread: 1 Guest(s)