Lucene search

K
openbugbountyG0bl1nsecOBB:1026661
HistoryNov 30, 2019 - 7:02 p.m.

jaivida.com Cross Site Scripting vulnerability

2019-11-3019:02:00
g0bl1nsec
www.openbugbounty.org
4

Open Bug Bounty ID: OBB-1026661

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: jaivida.com
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: XSS (Cross Site Scripting) / CWE-79
CVSSv3 Score: 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: g0bl1nsec
Remediation Guide: OWASP XSS Prevention Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAAjCAIAAADNIk3yAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAK90lEQVR4nO2cb0hTXxjHl01dehe5tmnOSCX0TVSEiZGFiFhEyOiPpZhlRVmUDOmvvciELEqlJCTCokAqfkiIL6IiIkZImclSsTWWrLWWhS6NpUtn5/fiwuF277l3t23XrfF8Xnn+Pef5nuesZ+ec0RyEkAwAAAAAJCAq1A4AAAAAEQvkGAAAAEAqIMcAAAAAUgE5BgAAAJAKyDEAAACAVECOAQAAAKQiLHJMWlra27dv+YqRSvjIDB9PAGHevn176NAhgQ7T09MlJSVfv34VaRBCD0hN6HNMf3//79+/V6xYQSxGKuEjM3w8AXyyZ8+e1NRUgQ7R0dExMTHHjh0TYw1CD8wCPnLMx48flUolsWl8fPzChQt8RfF0dnYWFRVxiwJTB9L68ePHhIQEP/wMLkzV379/r6io0Gg0Op3u5MmT09PT4u0Ir8PfeuI3YtzwuUOwkZDEKCgSAjHuc8bR0dG+vj6DwYBbf/36VVJSwrJsMBiePn0qxnjgoRepy+91AyIBJIjNZqMoSkyTQE9hsrOznzx5Qix6PB6Bgf612my2BQsW/L2bQYYps6ioqLS01OFwmM3m3NzcU6dOibfj97ITPQkE4XAgEa7iDqGKUeASJB3IMuLxePLy8rZt28ayLH6uoITe56L9lUtA5BHiu7IvX75YLJa8vDxiMTY2VmBsIK2hhSlzcnKyt7f3xo0bOp0uMzOzqampvb1dvCm5XJ6RkREUTwIk8AXHWgIU5TfhvGe4DA8PFxQUNDQ0+Dc8WKH/txYNmH1E5ZirV6+mpaUtXLhw165d4+PjMplsfHw8NTXV7XbPmTPnzp07zGJTU5NSqbx8+XJiYmJCQsLu3bsnJyf5LHd2dhYWFkZHR3OL+Bj++vXrNWvWzJs3T6PRbN++/fPnz7I/D+k7duw4f/48trlmzRraB1zz+fPnDRs2KJXKzMzMu3fv4nqiZSYzMzOnT59OTEyMj4/fvn376OgoXf/z58+DBw9qNJrFixefO3duZmaG9qexsTEtLS0+Pn7Hjh2jo6PHjx/XaDQLFy6sqKj4+fMnUfW8efM+ffoUHx9PN1mt1uTkZNq3devWKZVKnU63devWd+/eERdQp9O9efMGFx8/fsy31MQOTE+IM3JXgFZ64cIFjUazaNGimzdvyv685iJGn7VhiK5iLTqd7tWrVyIVMfuIlID9ZKoIigSZiE0lk8l+/fq1b98+pVK5ZMmSs2fPzszMEF3izshkyZIlZ86c8bk43FWiCUromR/DANcNiFiEjzk2m00mk+3Zs8fpdFqt1vz8/MrKSrrJbDZTFOXxeLxeL7M4NDQkk8m2bdtmt9utVuuyZctqa2v57G/atKmtrY1YxOfr69ev37p1a2xsbHh42GAw6PV69Ofpu729PSsri/7b6XQqFIr+/n7m2Vyv1zP9wfcwRMtM6uvrs7Ky+vr6HA5HVVWV0Wik6/fu3bt582a73T4wMLBq1arm5mZ6ocrKyhwOh8Viyc3NVavV9LrR3xarqqr4VGPMZnNycnJ3dzdCSKvVtra2ulyuoaGhpqamoaEhhJCaA8tCUlJSfn5+T08P13h3d3d+fn5SUhLf+hNn5K4ArbS8vHx4ePjRo0dmsxn9ec3FF33WhhFwVaQiriiRErCfTBXBkuBzuyKEampqdu7cOTQ0NDg4mJeXd+3aNaJLrBmJN07cSm6NdKFnXeUFN/RAZCAqx/z48YMudnV1paen4ybieww9xG630/UPHjzACcBut6empuIhbreboiiXy0UsEj9RVquV/qgwWycmJubPn0/P2NLSUlRUxGz1er0KhYLpD/GuH1tmotVqe3t7WZVer5eiKPpziBDq7OzMycmhVY+NjdGVL168iIqKmpiYwOu2dOlSokyMw+FIT0+/f/8+Qsjlcsnlcu5Nt4MDq4Pb7a6vr1epVMXFxRaLha60WCzFxcUqlaq+vt7tdjM7Y0/4ZuSuAK2U5b+Y6LMCSnSVC183rijxEogqpJBA3K4IIbVajQNhMpmys7OJLiHB9xi+SmaN1KHn5pgghh6IDP7uzZ/5GCuQYxQKBa4fHBzUarX0316v1+l04qYHDx7k5+fzFbHB3t7egoKC5ORktVqtUqloB1iz79y5s7m5GSFUUFDQ1tbGbKVPNkx/sASiZczY2JhcLqe/eTFxOp0xMTG4aLFYkpKSBBaKVWTJxOTk5NASsKKVK1dWV1c3NDQ8f/6c218Al8ul1+vlcjldlMvler0e5z8MyxPujMQVEP6XTiD6xIEsV0Uq4hMlUgLRmWBJ8LldXS6XTCbDJ1GVSkXb95lC/MgxUoee5Z4UoQf+dWb1zX/u3LmLFi3CRb5fLbPQ6/Xr1683Go0mk+nhw4dEy8XFxR0dHd+/f+/u7hb/c0wxlufOnSvSmkiIMr98+dLX13f06FFcc+/evdbW1uXLl09NTVVXV9NNGg5c+x8+fDhy5IjRaKyrq6Nr6urqjEbj4cOHP3z4IOAJcUaZBCsg4Kr4bkRR4SDB56byeDxRUVE9PT0mk8lkMvX19ZlMJonc+9dDD0QCwinIv3OMjHFk7ujowEdmJl6vV61W4xsnVhEb/PbtG/ObjslkIp5jPB6PSqW6cuXKli1bWK2su7KOjg7aAp9lJlqt1mQycT0n3pWJOcdwZWKb3EqmbykpKUjEXVllZSVFUdXV1SMjI8z6kZERg8FAURR+TuPzhDUjdwV8nmP4os8ayOeqSEVEUSIlEFUERYLI7UpRFPH6LujnGCRx6AXuygIPPRAZ+J9j3G63XC7H16m4iJ/+HA7HwMDAypUrmW/++NrXaDQuW7YM17OKzKm1Wm1LS8vY2JjFYtHr9cQPLUKotLR0/vz5//33H7eVfvPH/mAJRMvMi+n6+vrs7Gz62ZP+2kXX79+/v6ioiPXmLybHcGVyVwYhNDg4uHHjxmfPno2MjNjt9v3792/evJk4ikVZWZnNZuNrtdlsZWVl9N8sT/hm5K6AmBxDjD5rwwi7KlIRU5R4CUhEjvFbAnFT/fjxQy6Xm81m+vapsrIyJydnYGDA6XReunSprq6O6BJrRrvdzryMYrmNsVqt3G9LEoWe+OYfrNADkYH/OQYhVFtbGxcXd/v2bWaxsbGRoqiLFy9qtdoFCxaUl5fjp2+mtWPHjtXU1GBTrCKzs9FozMrKUigUSUlJ1dXVfDmmo6ODoih6Llarw+EoLCykKCojI6OhoQFL4FpmDfR6vSdOnFCr1QqFQq/X469dbrf7wIEDarU6JSWltraW+5sfvhzDlUnsPzU1VVtbm5GRERMTo9Vqy8rKhoeHuaMCgeUJ34zcFfCZY/iijzgbJriIl4B85ZhAJBC3K0Lo1KlTeKDH4zEYDCkpKXFxcZs2baKPFMSFZc7o8XgUCgXrkZw7qr29ffny5QILFcTQc49ZIQk9EM74yDF+wPdRYZGRkfHy5Uu+ong7/xZcmaFCIk8iIGrhLKGqqor4gxGMx+NJTU1tbW0V6AOhB2YT+ey/ANG8f/9eoBiphI/M8PEEEE9DQ4PwDwRiY2Pb2trWrl0r0AdCD8wmof9/l4lMT093dXWlpKSE2hEACCOio6NXr14t3Ec4wQDALBOyc4wwBw4c6OzsbG1tDbUjAAAAgP/MQQiF2gcAAAAgMgnTuzIAAAAgAoAcAwAAAEgF5BgAAABAKiDHAAAAAFIBOQYAAACQCsgxAAAAgFRAjgEAAACkAnIMAAAAIBWQYwAAAACpgBwDAAAASMX/i9mBGpLMfxkAAAAASUVORK5CYII=)

Screenshot: jaivida.com  vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 30 November, 2019 19:02 GMT
Vulnerability Verified: 30 November, 2019 19:17 GMT
Website Operator Notified: 30 November, 2019 19:17 GMT
a. Using the ISO 29147 guidelines
β€” β€”
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 30 November, 2019 19:17 GMT