Post
Topic
Board Reputation
Re: [ CWE-79 ] *.nastyfans.org is vulnerable to script injection
by
Boris007
on 18/06/2020, 14:42:16 UTC
I am also concerned that if what OP says really exists, has anyone taken advantage of it?

It does exist. To take advantage of it the attacker would have to coerce someone to visit attacker's site and nastyfans site at the same time (in the same browser session) and obviously have JS enabled. This is a serious hole. I hope there are e-mail confirmations or 2FA for any withdrawals etc.

Nastyfans is vulnerable to  CWE 601 open redirect vulnerability too.