Lucene search

K
openbugbountyKun-flyOBB:1167726
HistoryMay 21, 2020 - 3:43 p.m.

ass-reinigungen.ch Cross Site Scripting vulnerability

2020-05-2115:43:00
kun-fly
www.openbugbounty.org
6

Open Bug Bounty ID: OBB-1167726

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: ass-reinigungen.ch
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: XSS (Cross Site Scripting) / CWE-79
CVSSv3 Score: 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: kun-fly
Remediation Guide: OWASP XSS Prevention Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAA3CAIAAABVZQ1/AAAACXBIWXMAAA7EAAAOxAGVKw4bAAASBUlEQVR4nO2dfUxT5/fAr6VAhfLWlcpLmRS1c8ywjrAOFd2ixhlGSHWIjjFlSBANQ0KYA0IcqxkSRKNoCP+4qNucWQxBsihznTEd6xQVK2sYMiSlq4VVhMEqq7Vwf388+d7c333rBa0gns9f93k7z3nOc3pP7+m9t/NwHMcAAAAAwAsIZloBAAAAYM4CMQYAAADwFhBjAAAAAG8BMQYAAADwFhBjAAAAAG8BMQYAAADwFrM3xigUitu3b7MVgRcB2PS5x+3bt3ft2jXTWgDPjlkaY37//ffJycnXX3+dsQi8CMCmz0lycnJiY2NnWgvg2eEhxvT39wcFBTE2jY6OHjhwgK34hLS0tKSnp7MV5zwcZp9Sn1kLH+WJTR8ZGfn444/Dw8Ojo6M/++yzx48fT2+u/v7+sLCwaev8JGzfvv1NEitXrpyGkKe149Ozw7RnJ58ZHjx40NnZWVxczCjw2LFjixYt8vf3f+ONNy5evEieet7/8PHxUSgU+/fvn5iYoLcSHD16FDX5+Pj88ssvlIUQy6eMjYmJKS8vRw5GV49it2PHjikUisDAwLfeeuvnn3+m9GQT63Gl3JM+l+CcmM1msVjMp4mj5zRQq9WXLl1iK74IOJ3Op9JndsLHW4hNT09Pz8rKslqt3d3dKSkpZWVl05vLbDaHhoZOW+cnISkpiaPIk6f1EZueHaY9O3kg2zGO4/X19bGxsTqdzm63nzlzRiKR6PV6ck+n0+l0OsfHx41Go1qt1mq19FYCt9uNmjAMi4uLczgcjMunSDaZTCtWrKisrGRcL3lgfX19XFzc5cuXh4aGzp07J5VK29raKEtmFMtnpWyTPqfMxhhjs9lCQ0NdLhdjEZgDePQWYtPHx8flcjlxjmhvb1+8ePGU5rJarYmJiehArVZPW+cnAWIM/ZjYF0RUVNTly5eJ4pEjR9LS0timbmtri4+P96iY2WwOCAhITEwsKCggV1JiDHmIwWBYunQpYxN5IEXbxsZGQltusVNd6RyIMbx+jzl69KhCoXjppZc++uij0dFRDMNGR0djY2MdDse8efNOnTpFLh4+fDgoKOjgwYMLFiwICwvbvn37f//9h+Rcv3591apVQUFB0dHR77///h9//ME4XUtLy/r16319fSnFjRs3Hjx4EFXevn3b398fKYNh2M6dOz/99FPuDkuWLOEeTlHj+vXry5cvnz9/fnh4+ObNm+/du8exBJ5LQ9fCBw4cCA8Pj4yMPHHiBIZhjx492rFjR1BQ0MKFCz///POJiQnyJTM6PnTokEKhCAsL+/DDD5HalMvqgYGB9957LygoSKFQHDp0CF1fU/oQ191sMtnkMCrJLYfMxMREeXn5ggULAgMDN2/e/ODBA1RP9yu6D8yfP/+vv/4KDAxE9b29vVFRUfwNjmFYdHT0zZs30cG1a9dQ5Y8//sjWn9KBcaItW7Z8+eWXROfly5efOnWKw3psPHz4cOfOneHh4TExMV988cWUrMo4FmPx23v37r377rtBQUGvvPLKmTNnuLViE0KBzW/J7k05UZCHE/uCYdjo6KjNZktJSSFaV69e3dXVxaaeSCRyu90eV4FhmEAgOH369MmTJ3/66Sc+/f38/FwuF3cfura5ubnHjx/nI3aqK50DeI4xDofDaDQaDIb29nabzVZWVoZhWEhISHd3N7oezM7OJhc3btzocDja29tv3Lhx48aNjo6O2tpaJCotLS0nJ8disbS1taWkpIhEIsYZ2X6MSUtL0+l0qPKHH36YnJxsbW1FRZ1Ol5qayt1Bo9FwD6eo0dHRkZ+fPzg4aDKZ5HJ5YWEhxxJ4Lg3Zs7u722QynTx5ErmaVqsdHx/v7OxsbW3V6/WNjY30IZ2dnWgLLBZLRUUFXWxhYaGfn19vb69Opzt9+jTb7B5lsslhU5KPbrW1tTqdTqfT9fT0REVFoU8Uo18RMP4Cd+fOndLS0rq6OozF4OE02Jafk5Ozdu1a4hxH5vr162vXrs3JyUFFxokyMzObm5tRh4GBAaPRqNFoOKzHRlFRkc1m6+joaG1tbWlpaWho4G9VtrGMfltYWBgcHNzV1XXhwgVyjGGzGKMQCowuQXFvyomCzQ4Oh0MkEhFfKzEMCw4OHhsbY+x8//79yspKZHA+vPbaa1VVVbm5uYyhmszIyMi+ffvy8vK4u9G19fX1XbhwIR+xU1rpHIH7MgclNMfGxlDRYDDExcURTYy5MjTEYrGg+qamJpQZGB4eFgqFjD8hWCyW2NhYdOxwOMRi8fDwML1os9kCAgKQBLVaXVJSkpWVhWYMDg52uVzcHSwWC/dwDjv09vZGRESwLYFjaYz2JFaHkEqlRC4I5Zop6QXyFrS1taEtIPdxu90ikaivrw8Vm5qa0PU1fY+IekaZbHIYleSQQ0Emk3V0dNDtwOhXOM0HEFarNS4u7uzZszi7wa006MoQU1RXV0skkszMzJ6eHlTZ09OTmZkpkUiqq6vRYtkmGh8fRx6F43hDQ0N6ejq39RhzZW63WywWE/1bWlqSk5PpxmHbccaxFJDfIsXIH0lCMT4WQ0LoaRxGv6W7N8dvMIx9EH19feSMFoZhUqlUKpVKJBKRSFRQUEBsCrkVUVhYSBHrdruTk5O3bduG03JlZMkCgWDDhg1sKpE/PkRTaWkpGk524CmJpax07uXKhB6DkFgsJvItUVFRw8PDHoeIRKKYmBh0vHTpUovFgmFYWFhYRkZGcnLymjVroqKikpKS3n77bUKswWBAx5cuXVKr1USSgVyMjIxUKpUGgyE+Pt5ms+3bt0+pVE5MTOh0unXr1vn6+nJ3iImJ4R5OWcWtW7f27t3b1dXlcrkmJycnJyfZlsBWT/4eff/+fcKe5BTKyMjI0NAQcTfn5OSkUEjdFPIWyOVy+hbY7fbJyUmFQkHY3OMeMcpkk8OhpEfdRkdHh4eHExISOBSg+BXFBxAZGRnFxcVbtmzB2A0eHR3tceGIwMDA8vLygoKC3Nzc+Ph4dM9PfHx8WlpaX19fSEgI6sY20fz581NTU5ubmz/55JOmpiZ00TPVXbDb7S6Xi9wfnZswfjvONpbut3a7HcMw8keSkMNmMboQSgc2l6C4N0+EQiEl90X5IAQEBBiNRgzDBAKBTCbz8fEhdyZaiSJFvo+Pz+nTp1Uq1aZNm1QqFdvYvr6+4uLio0eP7tmzh6e2lZWVxcXFVqt1w4YNfMR6XOnc45mu7bvvvrt586bJZLLZbCUlJStWrDh27BiGYT4+PpGRkagP913LqampOp2ur68vLS0tJCREpVLp9Xpypou7g8fhZDQaTV5eXmNjo0gkInyIbQmM9WS/Z8PpdAoEghs3bhB+JhAIPGaEnzGMSk5JAuWkwA09UTYwMNDZ2fnbb78RNYwGpyfHiNBO5+7du/v27dPr9VqtFtVotdq6urrdu3drtdpFixZxTIRhWGZm5vHjx7Ozs9vb25uamvivztsw+i0bbBbzKOTp+i1Kpj1+/Jj4qjc2NhYcHEx0EAgEHF8guFsRS5Ysqa6uzs/Pv3DhAtvY6Ojo+vr63NzcPXv2oJzHxMQE4boOhwNFL7K2ISEhISEhdrudEtjYxHKvlGPS5xjuyxy2ZAtjE2OurLm5mfEuGqPRKJfLKZVut1sqlRIZAEoRx3GDwaBWq9PT0y9cuIDjeENDQ1FRUUREhM1m49PB43ACu90uFArJ2tKvWBmXwFFPNxpCLBbTU0ls6QXGC3aUDDGbzahIJEPGxsYEAgE568KdQ2OTw6gkhxwKMpnMaDTyHEjfdFRJqSFDGJx/rqygoEAsFpeUlAwNDZHrh4aGiouLxWIx+U4k+kQ4jjudTolEcuTIkU2bNhFKsllvqrkyPjvOOJbRbym5submZu5cGaMQuuty+y1jJcc9YJS7rerr6znutvI4KVvTO++8k5yczJGbunr1KpH1kslk5DuSGxoaiJRXVFTUlStXiKa6ujqiyaNYjpVyT/qcMv0Y43A4hEIhkcsmiijGZGRkWK1Wk8mkUqmqqqpwHO/q6tqwYQO6o9xiseTl5ZEti7Krer1+2bJlRCWliJDJZDKZDPW3Wq3BwcEqlYp/B+5WcuZdJpM1NDT8888/PT09Go0mNDSUbQncS+OwJ6KgoCA5ORl9U66trdVqtVONMTiOZ2RkaDQas9lsMpkSEhKIbVKr1Xl5eYODgz09PSkpKdwxhkMOXUluOWRLVldXq9Xqzs5Oq9VaWFio1+s5BjJuOkUgf4OzkZ2dTQQDOmazOTs72+NEWVlZwcHB33//PVHDZj22e5fz8vLS09MtFovJZEpMTKyvr8fZrTo2NiYUCru7u9HDH4xjcSa/xXFco9GQP5IeU/x0IZTZcU9+S0A+UVgsFpFIxDgj8dTI0NDQ2bNnuZ8aIcP9fAz9xw+xWMz4fIzT6ezq6lq9evXu3btR6/Hjx5VKpV6vRw/BSCQS4uxPPB9jt9u/+eYbiURiMBjYVKKI5Vgp96TPKdOPMTiOV1VVBQQEnDx5klw8dOiQWCyuqamRyWShoaHbtm0bHx/HcdzlclVVVSmVSj8/P5lMlp2dPTg4SJmltLS0oqKCkE8pIrKysjIyMohiUlISpQ93B45WymL1en1SUpJIJIqIiCgpKUGPazAugWNp3PZEOJ3O4uJiuVweEBCQmpra19c3jRgzODiYlpYmFotjY2NramqIbert7V2zZo1YLI6Pj6+vr/cYY9jk0JXkr5vb7d67d69UKhWJRBqNZmhoiEMBxk2nOB5/gz8h3BM1NzeLxWLk3gg26yX9f8hf1PLz86VSqVwur6qqYjwzktdeVlZGfOIYx+JMfovjuNVqXb9+vVgsViqVdXV1HmMMoxDy7LgnvyVDnCicTqdIJCK+mFJAJ24/Pz+VSoUyDYQFuGMMPT1z5MgRtoGNjY2U3/wJZDJZfn4+cd2P4/jhw4djY2P9/PyWLVvW1NRE0RY1JSYmkq9L+IhlW6nHSZ9HPMSYacDtENwolcqrV6+yFQGedHd3y2Sy2SNnSsyZTZ8R681+ioqK1qxZM9NaAM+O2XU/w507dziKAE+MRmNcXNzskTMl5symz4j1Zj91dXV87oUB5gwz897lx48ff/DBB3///feMzD4n2b9//4kTJ+7fv3/t2rWKioqCgoKZlfNiAtbziK+v75tvvjnTWgDPkKd+ZcQzV7Zt2zb0syrwVNDr9YmJiX5+fosXL0bJ6JmV82IC1gMACvNwHOcOQv39/XFxcVeuXFm1ahW5UqVSjYyMzJs3jz5ELBa3t7e/+uqrqPjtt99qtdrW1taEhIR///0XVd66dSs1NXVgYOApxUoAAABg1sErVzY5OZmTk/Pw4UN6E7o5r7u7OzQ0lLhXLy8vr6amhuhTW1tbUVFBeWpPIpE4HI4n1B4AAACYzfCKMQEBAaGhoaWlpfQmf39/f39/9KJA//+xd+/epqam/v5+DMMuXrzocDiys7OFQqFSqXy62gMAAACzGV4xZqrvx46MjMzJyUGvW66pqSkrK/Px8SG/ypuCxxetAwAAAM8jfO8r4/9+bERZWdmZM2fOnz9vNpuJ16SzwfGidQAAAOD5ZQr3LpeWlsrl8qKiIj6do6Ojt27dunXr1rKyMvorjSn09vauW7du/fr1W7Zs+fPPP/mrBAAAAMxmphBj0Puxz507d/78eT79d+/ejWFYbm6ux57oReu9vb0ulys+Pp6/SgAAAMBsZmrPYBLvxx4aGvLYOTg4WCgU+vv785F89+5d9LZE4kXrAAAAwPPOlJ/z37NnT3x8PON/r06bXbt2qVSqiIiInp6e8vLypygZAAAAmEGm876yr776KiEh4Qn/u83tdhMSHA6HyWTi+ENsAAAA4HlkOu8rUygUdXV1Tzix0Wh8+eWX0fHXX38NAQYAAGDu4fldMt7g0aNHS5curays3LFjx7OfHQAAAHg2zEyMwTDs119/Xbly5YxMDQAAADwbZizGAAAAAHOemfn/GAAAAOBFAGIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADeAmIMAAAA4C0gxgAAAADe4v8A9I9tDteQUkYAAAAASUVORK5CYII=)

Research’s Comment:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAA3CAIAAABVZQ1/AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAPAklEQVR4nO3dfUxbVf8A8DtosJTyXjoYMIpOIAshRAkBrToNEULIQubGCKKgEjQLm9hMA2xiRWUbQxMRCSFq2LLMxExciCG44FxqJYRhrZVh0y0MutLhLIyyUu+w7D5/nN/u7z73vYXb+bjv5y96X875nu89l7N77jjdRBAEBgAAAEgg5F4HAAAA4F8LxhgAAABSgTEGAACAVGCMAQAAIBUYYwAAAEgFxhgAAABSgTEGAACAVGCMAQAAIBXhMebWrVuvv/56WlpaeHh4ZmbmsWPH1tbWJIpmdnY2MjJy/cdIJDhVc9USQO1vvPFGeHj4iRMnAgjju+++i46OXlhYILc8/vjjhw4dwni7RHB6i2AqaAe43e4jR45sVOFBLmfDUbOx4UEGrdXMimZnZ2NjY9EPmyhSU1Obm5v//vvvIEcIEOEx5uWXX7bb7efOnbPb7T09PcPDwyaTKQiRgXVaWFjo6uoaGxurrq4O4PTi4mKtVtvW1oY+fvPNNzMzMy0tLRhvl/iH9Ja0tDSXy0V+XFpaam9vD+zcfx+/svE/SqlU4jiO47jX6x0aGrpw4QLZk0GwEby8Xq9MJltaWuI/bKPMzMwolcr1HyOR4FTNVYu/ta8/WqvVqlAopqenfT5fRkZGf38/wdslgtZbgp+KANzDjsqPGtiGBxm0VjMrmpmZiYmJYd1lNBqzsrKCHCFABJ5j7ty5g2GYTCZj7rp9+/Yrr7wSGRmZlpb2zjvvkFMiFy9eLCwsDA8PT0hI2LNnz9zcHHb3+fTIkSMJCQlJSUmff/45hmFra2vNzc2bN2+OiIjYs2cPOS3z8ccfp6enx8fHv/DCC263mzWwY8eObd68OTY2tqam5q+//kIbV1ZWXn311YSEhNTU1HfffXdtbe3q1asRERG//PILhmELCwuxsbE//PADtZy9e/d+8MEH5MfCwsITJ07QnqbJZ3AqdMyHH36Ynp4eGxv7/PPPU0NlJoc1A6y54mmgmPwjCwsLGo3G4/Fs2rQJzZUxk8N1XUiZmZn19fVNTU19fX1RUVE1NTUYb5fg2SUYOeuVQuEdP36cPxXMplGvoNvtpqWCdPHixSeeeCIyMjI5Ofm55577/fffMcpcCvUSR0RE7N27d2Fh4c0330xISIiPj3/ppZdWVlbIw/iD/PTTT4uLi8mPhw4dQskU0wrWkllzyN8nebLBesfxdzDM/97L2gNZb0DBqv0ll8txHF9nISAwAmNMREREaWlpZWXlTz/9hO4oUltbm9frtVgsw8PDBoOht7cXbTeZTPX19fPz85OTkykpKQ0NDWi7x+OxWq2Tk5P9/f1arRbDsI6OjpGRkZGREZvNtmXLlqmpKXSY2WweHR0dHx93Op1NTU3MqDwez8RdJpOpo6MDbT9w4IDT6TSZTMPDw4ODgz09Penp6S0tLY2NjRiGtba2lpaWPv3009SiKioqzp49i36+fv262WwuLy8XmTuPx2OxWFCodrsdzSPxJIeZAZ5csTZQTP6R+Ph4q9WKZgzQXBkzOVzXhaq1tfX8+fMtLS1dXV1oC0+X4NklGDnXlfJ4POPj4/yp4GoaEh0dTUsFqaysrLa21m63G41GrVYrl8tpJaPeaDQazWaz0+nMyspyuVwWi2VsbIycORQTZHl5ucFguHXrFvo4ODi4a9cuMa3gKpnr6vP0Sa5scN1x/B0M87/3sjaQ9QYUrNovbrdbr9eXlpaupxAQOMEnneXl5aampoyMDJlMtm3bNr1e7/P5CIJQqVQejwcdYzab8/PzmedeuXIlMTGRIIiZmRkMwxYXF6l71Wq1yWSibkGHLS8vo4+jo6MPPvggrUx0jN1uRx8HBgby8vIIgvD5fEqlcnp6Gm0fHBwsKCggCGJ1dTUrK0uv16tUqvn5eVppXq83KioKldbT07Nz506C8TTN+gxOC9VoNFJDZSaHNQM8uWI2kBaVYP6px3MlRzAqgiAqKyu3bt1K3cLVJfh3CUbOvFJiUsHaNOYVZE6PLC4uymQyHMe58oZqJ6f+jEZjSEiI1+tFH0dHR7dt2yYySIIgCgoKzpw5Q26n1cvVCtaSuXLI3ydZs8Fzx4m5wUmCvZerB7LegGKq5p8rwzBMdVdYWFhVVRVZIMyVBZnwGEPCcXx0dLSgoODw4cOLi4vUqxgXF6dWq9FhJpOpqKhoy5YtaDvXDOnS0pJMJqP9AuL65U47Ri6Xkx+npqZQ1U6nMywsjNxus9lQpycIYmRkBMOwrq4u1nZVVlaiXUVFRadOneIJg2cimxoqa3JYezZXrlgbSC2BJ/+syeRKjuD9ZrFYYmJisrOze3t7mXupXULkLv7IaVdKTCpYmyZmjCEIorKyMjc3V6fTdXZ2XrhwgXYwf2+k9grBIAmCOHr0aG1tLUEQ3d3dFRUVtEi4WsFaMlcOxdw+hLhuLKaD+dV7eW5P2g0opmpm5MR/XxGFQuFwOBwOR39/f2JiIvkvA9YTgaQEps6pHnjggcLCwq6ururq6n379oWEhExMTJCT7yEh/zftVl5eXldX19vbK5fLHQ5HSUkJT5mhoaHiAwjY/Px8SEjI/Pw8696Kioru7u7q6urx8fGBgYH1V4fjODM5q6urzCP9ypVgFeuPnOnAgQM6ne7JJ5/cvXt3RUUF7b0UtUu89957YnbxR85/pTbcl19++fPPP09OTjqdTp1O99hjj33yyScS1bVr1y40Ffntt9/W1taup6ggXH0xVQTce2loN6DH4xHTOoVCgeP42toa+TvE4/EoFArylOTkZAzDampqOjs7P/vss/379wcWHlgn4a5Jm1jHcdzn8yUlJSkUisXFxeS7kpKSMAz7888/nU7n22+//dBDDyUnJzMnuEnR0dFxcXG//vprAEHjOH7t2jX0s81m27p1K4ZharU6LCzs6tWraLvVatVoNBiGud3ugwcPnj59ure3F73UpSktLTWbzSdPniwqKkIve+Pi4rxeLzl77nA4/AqPKzk0PLlibWAAVZC4ksPv66+/np6ePnjw4FNPPaXValtbW9F21i4huEswctYrJZiKwJpGevTRR2tqapqbm7/44gvyxYC/BIPEMOzhhx9Wq9Xff//92NgY890AVytYS/b36gdAsAp/ey/PZaLdgCJbl5CQEBcXNzY2Rm4xGAw5OTnMIw8fPtzR0XH79u31JAQEjv8xx2q1qtXqvr4+p9O5tLRkMBiys7Pb29sJgnjttdcKCgrQvwE7Ojra2trQKWq1uqenZ2lpyWazlZeXc82VEQTR3t6en59vsVgcDkdDQ4PBYBA5V4Zh2O7dux0Ox+TkZG5url6vR7vq6up27txpt9snJycfeeQR9AC+b98+NDXx/vvv79ixg7WZVVVVUVFRX331FbklPz+/rq5ufn7eZrNptVoUxvLyskwms1qtPp+PP1RmclgzwJUr1gZSa+fJPzUkao2syeGZN/B6vRqNBk0eEgRhs9kUCoXFYuHpEjy7qLgiZ14pkalgNo3WLo/HI5PJbDYbNYypqamSkpLz58+7XC673V5XV1dWVkYENFcmJkiCIFpbW3NyclAtTKyt4OrqrDkUOVdGzQbPKYIdzK/ey9pAsijaDShYNdLd3Z2RkWEwGFwu15kzZ+Li4oxGI7NRBEFs376dnOwl34dRMd8ago0i/D5maGhox44dUVFRCoUiJyenr68PbcdxvLGxMSUlRaFQlJaWkm/zDAZDXl6eXC5PTEzU6XQ8Y4zP53vrrbdUKpVcLi8vL3e5XCLHGKVS2dHRoVarY2JiXnzxRXKy1ePx1NfXq1SqlJQU9LZ5YmJCqVSiN4o4jms0mpMnTzLbePbsWaVSSZ20vXLlyjPPPKNUKrdv397V1UWG0dTUpFAo+vv7+UNlJoc1Azy5Ym0gWTtP/mmJIj8yk8N1XZC2tjbau9bGxkb0q5+rS/Dv4kkOQRCsVwqFd/ToUf5UMJvGbJderyePR1ZXV/V6fUZGRlhYmFqtrq6uJv+jgb9jjJggCYIwm80YhlFjoOJqBWvJrDkUOcZQs8FzimAH87f3svZAhHYDClZN+uijjzQaTVhYWHZ29sDAANkK2tU/deqURqNZXV0l7o6CNKyvG8GG2EQQRDAelwDw3+zsbHZ2Njlp+c8kPsiVlRWVSuV0Opl/brXOkgH4x4I1MQEIknPnzmm1WpEDDAD/DjDGABAMbrcb/a/lex0IAEEFYwwAwUC+n7jXgQAQVMLvY9xud09PT3Nzc3ACCszs7Gxubu7NmzfvdSAAAAD+n/BzzP2wEjgAAAApwFwZAAAAqQiMMbSVwFlX56ZiXSuea6F75qLlrKdzVTo3N1dcXBwZGZmZmXn69GlqANR4yP/Gw/VVAhu+kDgAAABEYIyhrQTOv4g6wlwrnmuhe9ZFy5mnc1Xa0NAQFRU1NTU1NDREjjE8WL9KgCs8AAAAG0DwrzTJP5rlWp2bdjDGWCuea6F71uXQaadzVerz+eRyObUE1gUFqH+3zPwqAa7wBHMCAABADD/WXb5x48bq6mp6ejr6mJWVxboqg1KppP6V2c2bN10uF7n+3Z07d9ByqnK5PDU1lSzKbrezns5V6Y0bNzAMo5bAH7zb7V5cXGQumccVHgAAgPWT/Pep+IXug4D5VQJBWyQfAADuQ378Pg1sEXWulbrFLIfOU6larcYwjFoC+oFrWX6urxIIwjLpAABw3xIeY1QqFY7jly9fDg0NraysbGxsvHbt2qVLl/R6fVVVlZg60HeaXbp06fr168ePHye/sUqn083NzaGiysrKWM/lqjQ0NLSkpIRaAjo+MjIyLy9Pp9P98ccfly9fJr+cHMOwxsbG+vr63377bW5ubv/+/T/++CN/eAAAANZLzEsbciVwntW5Eda14rkWumcuWs56OlelDofj2WefVSqVGRkZnZ2d5Lt9rmX5mV8lwBWe2JdZAAAAeN2btf1h0XIAALgfwPttAAAAUoExBgAAgFRgjAEAACAV+K5lAAAAUoHnGAAAAFKBMQYAAIBUYIwBAAAgFRhjAAAASAXGGAAAAFKBMQYAAIBUYIwBAAAgFRhjAAAASAXGGAAAAFKBMQYAAIBUYIwBAAAgFRhjAAAASAXGGAAAAFKBMQYAAIBUYIwBAAAglf8A8dL+yvHEH9IAAAAASUVORK5CYII=)

Screenshot: ass-reinigungen.ch  vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 21 May, 2020 15:43 GMT
Vulnerability Verified: 21 May, 2020 15:54 GMT
Website Operator Notified: 21 May, 2020 15:54 GMT
a. Using the ISO 29147 guidelines
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 21 May, 2020 15:54 GMT