Lucene search

K
openbugbountyXav0OBB:1195821
HistoryJun 13, 2020 - 11:55 a.m.

sympygamma.com Cross Site Scripting vulnerability OBB-1195821

2020-06-1311:55:00
xav0
www.openbugbounty.org
6

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: sympygamma.com
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: XSS (Cross Site Scripting) / CWE-79
CVSSv3 Score: 6.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: xav0
Remediation Guide: OWASP XSS Prevention Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAA3CAIAAABVZQ1/AAAACXBIWXMAAA7EAAAOxAGVKw4bAAANAUlEQVR4nO3df0gb5x8H8KumGuzJ0jSmaWq31G22lOJkuCEsFGmlo0MkE3FWpM3+kXZYCUE6K2MEB1Zc2kkRN0YH3Q+2/SFlSCldCWxkIsV1IbXO2ZiWGG1qh3WmO9Zoj933j2PHfe9XzsSL0b5ff+Uuzz3P53nyMU+ey+XcxDAMAQAAoIGctQ4AAAA2LMwxAACgFcwxAACgFcwxAACgFcwxAACgFcwxAACglayYY3bv3n3r1i25TciwzI//2r7iyLcN7NatWydPnlQo8PTp06NHjz58+FBlhciWlVr7Oeb27dv//vvvK6+8IrkJGZb58V/bVxz5trE5nU6bzaZQYPPmzXl5ee3t7WpqQ7akIMkcMz09XVhYKPlUPB4/e/as3KZ6Q0NDtbW1cpuQYez4K7zuaRLnCf8V/+uvv959992ioqKdO3e+//77T58+VY4k/ThXJd/UhJH0D4SrZHp6euvWrWmGtFKr0oVswA/y0aNHY2NjLpeLe3Zpaeno0aOCnrpcLp/Pp6ZyvDulglEUiURIklTzlEJJZa+//vr169flNiHDuPFPJBJa1C/OE/4rXltb29TUNDs7Ozk5abfbOzo6lCNJOeskW09H0uFKGipXIBKJGAyG9ENaqfS7kA34QQoCTiQSVVVV9fX1gl6o7xfenVKwxufKHjx4EAqFqqqqJDchw/jjn5+fn+EWnzx5EggEPv/88507d+7Zs+f8+fODg4PKkeh0utLS0lVpPU3pDxfXlzQ7lbLMvOJraG5urrq62uv1pnY43p1SpDwFsTN8X1+fzWYzGo3Nzc2Li4sMwywuLnI1XLp0ib957tw5kiR7e3vNZrPBYDh27Ng///wjV/9nn33W0NAguTk6Omq320mStFqtdXV1ExMT/f39hw8f5gp3dnYeO3aMjdDr9dpstoKCgoaGhvn5+fb2dpPJZDQanU4nRVFcR8RRSdbJMEwsFnvrrbdIkrTZbF6vl/tcOTo6WllZqdfrTSZTfX397OysygC4GNSUFLciGDeapjs6Osxmc0FBQX19/fz8PLufoqiWlhaTyVRcXOzxeGiaVt8of/zFHwbZGgwGQ1NTE5sDckMqXuByoydIG3EC8H377bcHDhxY0Wfna9euraiAcr4xMuPMhtTd3W0ymSwWy8WLF/lLEMkxEXc8aagqe8Qvkw1dUM4KfotMGumqMkjJ5BHvVMgxfh9TyxZIvo6hKCoYDI6MjIyOjsZisY6ODoIgnnvuucnJSZIkE4lEc3Mzf/Ptt9+mKGp0dPTmzZs3b94MBAK9vb1ylSt8GVNTU+N0OqPR6PDwsN1u1+v1DofD7/f//fffXOG6ujouwuHh4WAwGIvF9u7dOz8/PzY2duPGjUgk0tnZyXVEHJVcna2trXl5eeFw2OfzffXVV1yEgUCgpaVlbm5ufHy8uLi4tbVVfQDqS0q2wtfb2+vz+Xw+XygUslqtExMT7P62trZYLBYIBK5duzY0NDQwMLCi8ORON1MUNTY2xuZANBpVHlIFgrRRaPHOnTvt7e2Cj5xFIoKjnE7noUOHfvvtN3GFv/7666FDh5xOJ3+ncr4R8uNMUdTk5OT4+PilS5fsdrtgrMRjIu64QqgqeyTuVJZ0QS4rxC2mk64qg0yZOGFSzpZnnfIUFIlECIJ4/PgxuzkyMlJSUsI9Jfl9DHtINBpl91++fLmiooJ9HI1GbTYbdwhFUSRJLiwsiDcXFhZ0Op34BHFlZeXg4CDXXCKRYJtjP1kzDDM8PJyTk8OtnEZGRl566SXlqMR10jSt1+vv3bvHFZY8Px4Ohy0Wi8oAuBjUlBS3IthpNpsDgYBgJ03TJElyYQ8NDVVWVqpvlD/+gnUMPweGh4fZHJAbUoV1jOBZQQJwZmdnS0pKvv/+e0H5WRHBgRRFdXd3G43GhoaGUCjE7gyFQg0NDUajsbu7m79oU5NvkuPMdpwftprkFwyLZKhicsXEncqSLihkhaDFdNJVZZCprWMkEyblbIGVfefPf79QmGP0ej23f2Jiwmw2s49pmo7FYtxTly9fPnjwoNxmY2NjeXm52+32er0///wzu7Onp8fpdDIM09/fLz6rw0i9o7GbClGJ64zFYnl5efzCXJ2BQKC6utpqtbKLd4PBoDIA9aFKtsLwLC4u6nQ6mqaZ/ycIOxQKsVOgykb546/wh5p0SNXPMYJXnFNZWXnhwgXJ1tVYWFhwOBw6nY7d1Ol0DoeDe9viJM03uXFWeJNSSDPJjghCVdkjuU5lQxdUZgWTXrqqDDK1OUZybFPOFsjod/65ubk7duzgNpWvWv7uu+8uXrxYVla2vLzsdrtPnTpFEERdXd3Vq1cJgrhy5Qp7Uit9K6rT4XAcOHDA7/cHg0H2KC2oaSU3N3d1G838dZmSLT548GBsbIx9uQWSnisjCOLu3butra1+v7+rq4vd09XV5ff733vvvbt37yq0LplvhAbjrBCq+mKSncraLqwvkmO75tmyjilPQamtYwjeMvaHH37glrF8NE2bTCZupSzYFAgGg8XFxezj/fv3+3w+g8HAnr1R/8FHISpBney5skgkwj7LnSv7888/+Z8lg8GgFusYyVYEA2I2m4PBoGCn3MkHNY0Kxl/lOkZySB8/fpyTk8M/tya5jpF7xWma5u9c0bmyEydOkCTpdrsFX7fOz8+7XC6SJE+cOMG1oibfJMdZeREgl2aCo+RCVdkjyU5lQxfkDhe3mE66qgwy5e/8BWObTrZA6usYk8mUSCSmpqYkN91u9/3793///XePx1NTU8MdtbS0xD4YGRmxWCy7d++W3Pzjjz+OHDny008/PXr0aGZmpr+/v7y8nH2qrq7O7Xbb7fYUfnwnF5Wgztzc3JqaGpfLNT09zRZmixUVFRmNxk8//TQej09NTXH7V5dcK9zQEQThcrlaWlpu3759//79U6dO/fLLL2zYjY2NLpdrZmaGDbupqUllo4LxV088pIWFhRUVFW63++HDh1NTU+xFIhwuT+RazM3NtVqtkm3tFBEUoChqfHz83Llz27Zt4+/ftm3bJ598Mj4+TlGUZH/l8k1ynFMYE0L0ByIXqsoeiTuVVV2Q+0PjSyddVQaZk5ND03TSemia1ul0/D2CsdU0WzY+5SlI+WOFx+MpKChgL2TkNtlrl3t6esTXLvNra29v7+zs5KoSbC4vL3s8ntLS0ry8PLPZ3NzcPDc3xz4VDAaJ/66eTBoh/4OPXFTiOhmGmZubq6mpYa9d7unp4er0+/0VFRV6vd5isbjdbo2+j0naCk3Tp0+fNplM7OV2Sa9dTtqoYPxVrmPkhjQcDh88eJAkyX379l24cEGwDmPz5MiRI/wWFSJc6fcxaqjMN8lxVl4EKKSZ4O9ldWVJF+QOl3wdU05XlUEmEgm9Xi+4pEIcyeDgYFlZmcLYppMtkGSOSYHKN4XS0tIbN27IbSqgKEqv14svRkonKuU6JycnuW8UNyr1489J890/hRZXkUatazQjZlKaXcjMCKhvpa2tTfK6Ek4ikbDZbOzvdeSsba6ud7pk6xyt3LlzR2FTwfXr1+12++re0Em5zmAwWFJSsorNZSH1479+W8ye1iFjvF4ve5ZCTn5+/jfffPPGG28olEG2pGPN5pjUxOPx/v7+xsZGrev86KOPrFZrbW3tvXv3Ojs7P/zww1VsEQAyY/Pmza+99ppyGeUJBtK09vf2XxHu9KvWdVZVVQ0MDBQXFzc3N7e1tR0/fnwVWwQAeEZsYhhmRQdMT0/v37+fu/mKpHg8PjAwcObMmfRiAwCA9W3FcwxBEEtLS8q3aFUzDwEAwIaXyrmyDX8PcAAAWBWq/g/m2bNni4qKduzY8cUXX/D/W19hYeHHH3+8ffv2rVu3Hj9+/MmTJwRBxONxm81GUdSmTZu+/PJLgiB+/PHHDPQEAACyjap7+2fmNuYAALDBqDpX1tfXt3379jfffHPPnj2Cp86fP79r164XX3yxq6vrypUr7E72vynk5+ezd4gLh8PV1dWHDx9+5513uBtRAADAhpd8jiFJUu7HiXq9fteuXezjvXv3RqNRyWJbtmw5c+ZMOBxeXl7et29fyrECAMD6kqHfx2zIe4ADAICytOaYRCIxMzPDPg6FQs8//7xksZMnT5aXl1ssllAohB/NAAA8O9K9l4zb7e7r61tcXPR4PA6Hg93J3V775ZdfJv67B/gLL7yQbrAAALCupLWOIUmyoqLi1VdftdvtZWVlp0+fZvdv2bLlgw8+KC8vZ69d/vrrrzHBAAA8g1L5nT8LP+YHAABl6+yemAAAsI5gjgEAAK1gjgEAAK2k/n0MAACAMqxjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK5hjAABAK/8DV0p/65/DcNcAAAAASUVORK5CYII=)

Screenshot: sympygamma.com  vulnerability

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 13 June, 2020 11:55 GMT
Vulnerability Verified: 13 June, 2020 12:08 GMT
Website Operator Notified: 13 June, 2020 12:08 GMT
a. Using the ISO 29147 guidelines
β€” β€”
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 13 June, 2020 12:08 GMT