This post is from a low-reputation account and contains an unverified outbound link. Be cautious before clicking external links.

Stored XSS in Yahoo!

Words
135
Reading
1 min
Listen
Play
8y

Sharing is Caring :)
When we share, we open doors to a new beginning...../

Well, This is Shahzada Al Shahriar Khan. And I am from Bangladesh.
Now I am going to share how I found Stored Cross-Site Scripting (XSS) in Yahoo.

Steps to Reproduce:

Go to https://www.yahoo.com/news

Screen Shot 2018-04-27 at 11.17.54 AM.png

Comment this payload: "><img src=x onerror=confirm(1);>

Screen Shot 2018-04-27 at 11.18.57 AM.png

Now what? Voila! We get the famous confirm(1) to popup! :D

Screen 1.png

I am trying another payload that I can write something in popup box, and found this payload: <img src=x onerror=prompt(1337)>
That moment I feel like a boss!

Ironman.jpg

Screenshot 2.png

Here is the video PoC:

Timeline:

31/03/2018 - Initial Report.
01/04/2018 - HackerOne staff asked for 'Needs more info.'
01/04/2018 - More Info Submitted.
04/04/2018 - Triaged and a $300 initial bounty rewarded.
06/04/2018 - Bug Resolved.
11/04/2018 - $1700 bounty rewarded.

Thanks for reading..../

./TheShahada

Stored XSS in Yahoo! | Ecency