Lucene search

K
openbugbountyG0bl1nsecOBB:1165310
HistoryMay 18, 2020 - 7:54 p.m.

blautango.com Cross Site Scripting vulnerability

2020-05-1819:54:00
g0bl1nsec
www.openbugbounty.org
6

Open Bug Bounty ID: OBB-1165310

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: blautango.com
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: XSS (Cross Site Scripting) / CWE-79
CVSSv3 Score: 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: g0bl1nsec
Remediation Guide: OWASP XSS Prevention Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAA3CAIAAABVZQ1/AAAACXBIWXMAAA7EAAAOxAGVKw4bAAANbklEQVR4nO3db0hb1xsH8FSjphpbtUlqNcM/rG5IcWFz4pgbpZWuOJF0s+3audUyae1wImK36sbmHNjOamF9EcZw4P7A9qKUIaU4CDKCSFdduGbBaZoWzVzMRnTqbtto097fi8vvcrn/jd4Yy/fzynNzzr3Pc85ZHnO0bgtFURoAAAAVxG10AAAA8NhCjQEAALWgxgAAgFpQYwAAQC2oMQAAoBbUGAAAUEvs1pi8vLyxsTGxJsSOGFmaGAkDlBgbGztz5oxEhwcPHhw7duzvv/9WcjcsfSyL0Rrz+++/P3r06JlnnhFsQuyIkaWJkTBAodra2tzcXIkOCQkJiYmJLS0tsrfC0sc4mRozPT2dmpoq+NLi4uL58+fFmmvU399fVVUl1owCscQlJkSJ9Z2lWMAszb///nvy5Emj0Zidnf3BBx88ePBgVfdZ48Suyw5RGIPsIjL3mZ6eTk9PX2NUq6Uki4j3YcTLxH7i3Nycy+VqampiXl1eXj527Bjnzk1NTXa7XfbO0Vx6iEDkn2MWFhY6OzvFmmu04TVGJes7S7GAWZra2tqVlRWCIAYHB4eHhz/++OMNCWMtcnJygsGgbLcYX0QlWUQ/BfYTSZJMTk5OSkqim8vLywcPHgyHw5whGRkZJEnK3jmaSw8RiMWzstnZWY/Hs3fvXsEmxA5mae7fv+90Or/66qvs7Oynnnrq0qVLV65cWdWttFptQUHBGsOIbDgb88a3Fkwua0lqLdYli6gJBALl5eXd3d0RjI21pQc+RTXmiy++yMvL27Fjx1tvvbW4uKjRaBYXF3Nzc0mS3LJlyzfffMNuXrp0KTU19eLFizt37kxPTz9x4sT9+/fp+4yMjLz00kupqanZ2dmvv/76H3/8Ifi4/v7+AwcOJCQkcJqHDh26ePEifXFsbCwpKYkORqPRnD59+uzZs9Iddu/eLT2cH8nnn3/Oz4JtZGTkhRde2Lp1q9FoPHz48F9//aXhfe5mDkw4kyY4nB7b09OTl5eXnp7+5ptvMkFqNJrZ2dlXX301NTU1Ly+vp6eHOYe5e/fu6dOnjUbjE0888emnnz58+JAT58OHD1tbW3fu3JmSknL48OG5uTmxgewAUlJSjh49Ojc3d/bsWaPRuGPHjpMnT969e5e/Ulu3bv3zzz9TUlLo616vNysri5kiJYuenZ3922+/Mc2ff/5ZsJtgB86GEXwifwboTM+fP280Gnft2vX111+zF47+mr+N+YvID5XJJTs7+9dff1WYEbuPwhSYOAWzWEsKGpG9zbG8vPzOO++kpqbm5OR88skn9Mbjh8R/IltOTs6HH34oOzn8WdJEd+khMvI1hiRJgiCGh4dv3rzp9/vPnTun0Wi2b98+MTGh1+tDoVBNTQ27eejQIZIkb968OTo6Ojo66nQ6u7q66FtVVlbW1tb6fL6hoaGysjKdTif4RLGDssrKSuZ89tq1a48ePRoYGKCbdru9oqJCuoPVapUezk989P/YWbA5nc5Tp04FAgG32202mxsaGiRmkjNpYsNJknS5XPSE+3y+trY25g4NDQ2JiYler9dut3/77bfM9cbGRr/f73Q6BwYG+vv7bTYb59FdXV12u91ut3s8nqysrPHxcYmB9IoPDQ0RBOH3+59++ulgMOhyuW7cuDE1NcWOR/CYYnJysqWlhfm2VHDRjTycm9TW1u7fv59ddRgjIyP79++vra0VC0PwiYIzQJLkxMSE2+3u6+srKyvjPEhwG/MXUSJUhRnxk1KegnQWa0lByd7u6Oi4d++ey+UaGBhwOBxffvmlYEj8J0ZmY5ceIkRJmpqa0mg0S0tLdHN4eDg/P595Sa/Xs3vSTXqIz+ejr1+9erW4uJiiqPn5ea1WGwqF+E/x+Xy5ubn01yRJ6vX6+fl5ftPv9ycnJ9N3KCkpaW5uPn78OP3Ebdu2raysSHfw+XzSw/mJ87PgZM3m9XozMzMFZyYtLU1w0vjDORM+NDTETHg4HNbpdHfu3GFCom8bDof1ej1zvb+/v7S0lHNzk8nkdDo5FwUH0gEsLCwwAcTFxd27d49uDg8PP/nkk/TXnJWizczM5Ofn//jjj3RTbNFneDgdSJLs7OzMyMg4cuSIx+OhL3o8niNHjmRkZHR2dpIkKRiG2BP5M0Bnyo6fvTpiG4DiLaJgqHxi3fhJKU9BOot1TEFsbxsMBmYhCIIoKSkRDInizS3/vwL+RfaVGFl6iIB8jVH4dsne2Tqdjrk+Pj5uMpnor9944w2LxdLc3Nzd3f3LL78wfcLhsN/vp7++evXqvn37mJc4TYvFMjg4GAgEzGbzwsKCyWQKh8O9vb2vvfaakg6yw9npCGbBydrpdJaXl2dlZRkMhoyMDHpylE8af7jEWL/fn5iYyA6Jfolz3ePx0G8HjIWFBa1WGw6HOTkKDpQIgNPkLA2ttLT08uXL7Ctii67E/Py81WrVarV0U6vVWq1Wpv6JhcF/ouAMSL+pSWxjwbdITqgKMxJLSmEK0lmsMQXZvT0/P6/RaAz/l5GRIfjfCP+JEdSYGFl6iEBUf+b/ww8/9Pb2FhUVraysNDc3v/fee/T1+Pj4Xbt20V9L/0ZZRUWF3W6/du1aZWXl9u3bLRaLw+Fgn3RJd5AdvlpWq/Xll192OBwEQVy/fj3Kw1clPj5+fW/IPyibnZ11uVzMstIEF132rEyj0dy+fbuhocHhcHR0dNBXOjo6HA7Hu+++e/v2bYkwJLbZeuQtgB+q8m6CScVCCrKbMxQKxcXFjY6OEgRBEITL5SIIQqXwYnbpQZ50CYrsc4yG9Unzp59+EvykSRCE2WzmXAyHwwaDgTm94TQpihoeHi4pKamqqrp+/TpFUTabrbGxMTMzk/kYJN1Bdjg7HcEs2Fn/888/7G9ICYKgJ2dpaSkuLo593iU4aYLDJSacPiubmpqim6s9KyMIgj/bgmdlSj7H8JeGvsi5wsEsuuxZWX19vV6vb25uDgaD7OvBYLCpqUmv19fX14uFIfhE/gzIfjMrto05A8VCVZgRPynlKUhnsZYUxPY2Z6Berxc8vlv3zzFUbCw9RCDyGkOSpFarZU5vmSa9QtXV1TMzM26322KxtLe3UxQ1Pj5+8ODBwcHBYDDo8/nq6uoqKyuZO9OnqA6HY8+ePcxFTpNmMplMJhPdf2ZmZtu2bRaLRXkH6VeZw1yxLJaWlrRa7cTEBP3p22Qy2Wy2hYUFj8djtVqZySkpKamrqwsEAh6Pp6ysTGzS+MOl3+Krq6utVuvU1JTb7S4qKmJeqqurq6qq8vl8brf72WefpU+r2AfTnZ2dJSUlLpdrZmaG/nZVbKDCGiO4NJyHUnKLLqGmpoappnxTU1M1NTWCYYg9kT8DSt5o+BuA4i2idKgKM2InpTwFSkGNiTgFwb3N2f/19fWlpaVut9vv93d1dXV0dAiGxHmiz+djH0ZxwmZ4vV723uPM0oYsPUQg8hpDUVR7e3tycnJfXx+72dPTo9frL1y4YDKZ0tLS3n77bfonxisrK+3t7QUFBYmJiSaTqaamJhAIcJ7S0tLS1tbG3J/TpB0/fry6upppFhcXc/pId5B4lf+tVldXFycLiqLOnTvHZO1wOIqLi3U6XWZmZnNzMzM5Xq933759er2+sLDw8uXLYpPGHy494YFAoLKyUq/X5+bmXrhwgV26Tp06ZTAYzGZze3t7OBzm3CccDr///vsGg0Gn01mtVubbVdmBYjVGcGk4nSnJRV8X/DDEnsifAdk3GsFtTOPs/PWlPAVKrsasJQWxvc3e/6FQqKmpyWw2JycnV1RU0J8qBGsM+4mhUEin03F+uYA/6sqVK0VFRWLhbdTSw2rJ1JgIiO0wJQoKCm7cuCHWBLaJiYkN/FFkjCyNemGsZRvHiFhOobGxkf8LI2yhUCg3N7e3t1esA5Z+s9BG96c/MiYnJyWawEYQRH5+/kY9PUaWJkbCgNXq7u6W/gWBpKSk77///sUXXxTrgKXfLGKrxoC0zz77LCsrq6qq6s6dO21tbVH+m2AA6yUhIeH555+X7iNRYGATicW/VwZi9u7da7PZzGZzTU1NY2PjiRMnNjoiAAApWyiKku6xuLhos9laW1ujExAAADw25GvM9PT0nj17/vvvv+gEBAAAjw2clQEAgFpkPscsLi6mpaXRX/f19WVmZr7yyitRCQwAADY9+bOyycnJ4uLiYDCo1WrNZnNhYWFXV9dzzz0XnfgAAGDzkj8ro/8fDElJSfHx8V6vt7y8/MCBA0ePHr1165b64QEAwCa2up/HpKSktLa2er3elZWVwsJClWICAIDHw6p/5q/wz5gDAACsrsacOXPGYrFkZmZ6PB78ixkAAJAm/7dkDAZDKBS6devW7t27SZJ0u905OTlRiAwAADY7+RqTkpLy0UcfWSwWm8323XffRSEmAAB4PMj/7jIAAEBk8O/8AQBALagxAACgFtQYAABQC2oMAACoBTUGAADUghoDAABqQY0BAAC1oMYAAIBaUGMAAEAtqDEAAKAW1BgAAFALagwAAKgFNQYAANSCGgMAAGpBjQEAALWgxgAAgFpQYwAAQC2oMQAAoBbUGAAAUMv/AKo6DEYa1W5OAAAAAElFTkSuQmCC)

Screenshot: blautango.com  vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 18 May, 2020 19:54 GMT
Vulnerability Verified: 18 May, 2020 20:04 GMT
Website Operator Notified: 18 May, 2020 20:04 GMT
a. Using the ISO 29147 guidelines
β€” β€”
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 18 May, 2020 20:04 GMT