Lucene search

K
openbugbountyTeamhashOBB:1161672
HistoryMay 15, 2020 - 8:02 a.m.

sweetlavka.ru Cross Site Scripting vulnerability

2020-05-1508:02:00
Teamhash
www.openbugbounty.org
9

Open Bug Bounty ID: OBB-1161672

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: sweetlavka.ru
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: XSS (Cross Site Scripting) / CWE-79
CVSSv3 Score: 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: Teamhash
Remediation Guide: OWASP XSS Prevention Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAAjCAIAAADNIk3yAAAACXBIWXMAAA7EAAAOxAGVKw4bAAALxUlEQVR4nO2db0hb1xvH79I0DeEutWl+wUkoWRkySnGhOBHqSmmllBBCJhJaCVsoIk7SEIIvxBdFXMlEMih9IX0hRUrZxhgiUsQXUkYQKZkLt2kIWbCSBrlNS+aiXCS1oWcvDr/D/d1/+dPGxPyez6s8595zzvN87zk+95wc9SOEEAUAAAAANUBVbwcAAACApgVyDAAAAFArIMcAAAAAtQJyDAAAAFArIMcAAAAAtQJyDAAAAFArGiLHfPrpp0+fPpUzAT5NIE4ThFAFT58+/e677+rtxQGhHOzbt2+vX7/+6tUrSRNoMuqfY549e/bu3bsvvvhC0gT4NIE4TRBCdXg8HovFUm8vDgjlYI8eParRaEZHRyVNoMkokWNevHjx8ccfS17a2dn54Ycf5MzyWVxcdDgccmZN4fusEKkC1dWqGiIO6ffFixcnTpyQLGlMqnu+H1Dn8vWRk/TNmzfXr1+vyJ+///47Fov5/f5KvW0EKp3a4mDFivn9/pWVFTkTc3gHOcCn+nVMPp8PBoNyZvnUMcdU7XO9OEhxasRhD+HNmzdXr14tFosV1eI4TqfTHTt2rEZe1ZRKp4kgWEnFDAYDx3FyJtBM1Hmv7OXLl6lU6uLFi5ImwIcvjlqtbm9vV/7QgByu5yspaTab7e3tDYVCdXXtMFG1Yod0kANCkCLpdJqm6Tt37lgsFoPB4Ha78/k8Qiifz5MW5ubm+OaPP/5I0/T09LTJZGppafnmm2/29vbk2r93757L5ZI0I5FIT08PTdNtbW19fX2JRMLpdE5PT+OrDMNoNBrsDEJoaGhodHQUIVQoFG7cuEHT9KlTp27dulUsFuUKBSHgSIknkUiku7tbq9Uajcb+/v6trS2EkMvlun37Nrmnu7sbB4vNeDxuMBjC4bBCC2Jtg8Gg0WhsbW2dnZ0V+JBOp1taWuS0Kofl5eUybxCrLRnv3Nwcy7I2m42maYvFEgqF+B6W9IEfAsdxQ0NDRqPRbDZPTEzgh4IVCIVCFoulpaVlYGAAP2KBMnLV5TTf2tq6cuUKTdPt7e3BYLCkzyUR+6Mstfj+ijoSzybx4EFlSKrT6VwuVy6XGx0dNRqNBoPB4/FwHKfQkWCaVCeOuFDZrIiSgxyoL6XXMRzHMQyztrYWiURYlh0bG6Mo6vjx48lkkqbpQqHgdrv55tdff81xXCQSWV9fX19fj0aj09PTco0rbJTZ7XaPx5PJZFZXV3t6erRard1uJ5u2jx49evfu3fLyMjZXVlZsNhtFUZOTk3t7e7FYbHl5ORwO37t3T65QEILAsWg0OjQ0lM1m4/G42Wz2er0URblcroWFBXzDy5cvGYa5cuUKNnd2dvr6+qampr766iuFFsTaJpPJeDw+NzfX09Oj/CCq2GXyeDyXL1/+888/xZf++OOPy5cvezwebIrVlozX6XR6vV6NRrOxsbGysvLgwQOF3gVdCELw+Xwsy0aj0eXl5cXFxZmZGVzOcVwsFsPjLZPJjI+PSzYuWV1Oc6/Xq9frE4nE0tLSTz/9JNngf0QohCZGQerykfRBbjaJB4+CpAzDrK6uMgzDsuznn3+ey+VisdiTJ0/S6TRRWLIj5WnSCHwQ5YEaopyC0uk0RVG7u7vYXFtbO336NLkk+SaCq2QyGVw+Pz/f2dmJP2cyGYvFQqpwHEfT9Pb2ttjc3t5Wq9WFQoHvDMuyOp0OF3Z1dQUCgYGBAdyjXq/f399HCBmNRvxehhBiGKarq0uuUBCCwpvUxsZGa2srQmhvb0+v1+PQZmZmHA4HqWWz2UZGRuRkJC2ItSXhS0pK3rgFWpUJx3HBYNBgMLhcrlQqhQtTqZTL5TIYDMFgEMsiqbZkvMViUavVbm5u4hvm5+cl1wTiLgQhFItFmqZJO4uLi93d3Ug03lZXV/F4EygjV50P0Rz7zB+Qkj5viVAQVnJdJZZa4X5JxD7IzSbx4FGWlKz4V1dXVSoV2VpYW1v77LPPkOK0rXSRccDrGGXlgbpT1l4Z3yTzUyHHaLVaUp5IJEwmE/5cLBZZliWX5ufnL126JGdeu3bNarUGAoFQKPT777/jQqvV+vjx42w2azab8/m8yWQqFouzs7N9fX0Ioe3tbYqijP/FYDCYTCbJQnEIgnCi0Whvb29bWxuuQqK+du3a3bt3EUK9vb0PHz7EtcbHx1Uq1f379/nSybUgp62y2gJxKmJ7e9vpdKrVamyq1Wqn00l+6JC4xGqL42VZVqPRkKuJRELy57VkF/wQBO2kUimcD+QUEJTLVZfUnGVZwYCsxV4ZRiB1yfvL6UhyNokbrFRSgakwbRs8x2DklAfqzoF+53/kyJFPPvmEmMonyn7++efZ2dmOjo79/f1AIHDz5k2Komw228rKyqNHj+x2+/Hjx61WazgcJhtlhUJBpVKtr68zDMMwTCwWYxhGsrCkq06n88KFC+FwmGGYpaUlUo63j/75559IJIK93dvbm5+f/+WXX8bGxnZ2dkq2UB1VH8d6/vy51+sNh8OTk5O4ZHJyMhwOj4yMPH/+nNwmqTYlFW85SHZxACfK3kfz99wro6SkrpT39+H/k/dXHqghyimounUMxVt0LywskEU3n2KxaDQaydJeYApgGMZsNiOE1tbWurq6HA7H0tISQmhmZsbn87W2tpLlEU3T0WhUUF2yEMmvY16/fs1/IWIYhkRdKBQMBsOdO3fwyimdTqvVavwNud1u93q9JVuQ7B2zu7urUqn4O0W4lrI4CgwPD9M0HQgEcrkcvzyXy/n9fpqmh4eHxbWI2uJ48b5TOp3GV+X2ncRdiB+33MZOOesYyepymgv2yhYWFmqxVyYntdz9kpTcKyOzSdxgpZIKTIVp2+DrGGXlgbpTfY7hOE6tVpMNUGLiwYpP9cTjcavVOjExQVogm/7hcPjs2bOkXGAmEomrV68+fvw4l8tlMpnBwUG73Y4vmUwmk8mE29na2tLr9VarlVQcHh7u7u6Ox+Msy05PT09OTsoVCkLY3d1Vq9XJZBKfxjGZTDMzM/l8PpVKOZ1O/rQcGBjQ6/W//vqrQJ9kMqnVamOxGPFTsgWigOS86urqGhwczGazqVSqp6cH1xKIUz5ut5vkAzHpdNrtdiNFtQXxIoT6+/udTmc6nY7H4x0dHcr7TqQLcQiDg4MOhyOTycTj8XPnzuEdObnxJng6ctXlNHc6nfwBWYu9MmWpM5kMfyeqoo4kZ5Pk4KlIUoGpMG0FM70kksEK3NjY2OC7ITArQll5oO5Un2MQQhMTEzqdjpxoxCY+zjs1NSU+u8xvbXR0dHx8nDQlMPf39ycmJtrb2zUajclkcrvd2WwWXxoYGOjv7yd3dnZ28isWCgW/3282m3U6nc1mw691koXiEMbGxsjncDjc2dmp1WpbW1sDgQA/6oWFBZqm+UdIySWfz3fhwgX8WbKFkqcMNjY2Ll26RNP0mTNn7t69i2sJxPngKKgtiBchlM1m7XY7Prs8NTVV5o8GcQgKB23JPfzxxn86ctXlnhr/7HI5561LUul7d6FQ0Gq1VXwjjTsSzyZJByqVFP1vjpGbtog3TcoJXDJYQcXffvuto6NDzgSaiRI5pgrKnH7t7e1PnjyRMwE+DStOMpkk3wwr07AhHBg+n6+KUxvv/2X4h+2ozNuUgy0UChaLBf9Oj9gEmgx1fb4Foqi//vpLwQT4NKw4DMOcPn26nDsbNoQDIxQKlXPYpPEp5y97Kgd77Nixhw8fnj9/XtIEmoy65RjgkPL999+3tbU5HI7Nzc3x8fFbt27V26PDwdGjR7/88kuKouROi21ubh7k31etDpqmya/lKgeCg5VDkFEgwTQxkGOAyrh48aLf7x8ZGTl16pTP5/v222/r7dEhQ+4Fv/ETDEVRJ0+ePHnyJP58qAMBDoyPEEL19gEAAABoTur/P8oAAACAZgVyDAAAAFArIMcAAAAAtQJyDAAAAFArIMcAAAAAtQJyDAAAAFArIMcAAAAAtQJyDAAAAFArIMcAAAAAtQJyDAAAAFAr/gUnBvthTO8dPAAAAABJRU5ErkJggg==)

Screenshot: sweetlavka.ru  vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 15 May, 2020 08:02 GMT
Vulnerability Verified: 15 May, 2020 08:08 GMT
Website Operator Notified: 15 May, 2020 08:08 GMT
a. Using the ISO 29147 guidelines
β€” β€”
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 15 May, 2020 08:08 GMT