Stored XSS on Edmodo main domain




Hey Guys, Today I would like to show you how I found a Stored XSS on Edmodo main domain.

when I test the website I create two accounts when I signup I added the XSS payload on the name, I opened the victim account on FireFox and attacker account on Google Chrome and I opened the victim profile and send a request to connect together like add friend now when the victim open my profile to accept the request the XSS payload which was in the name will be executed




The POC Video




I hope this topic helped you, thank you for reading.

Comments

Popular posts from this blog

HITB2018DXB Pre-Conf CTF | Write up

Write-Up || Quals: Saudi and Oman CTF 2019 Web Challenges

Steal some JSON response by JSONP injection!!