Closed Bug 1761650 Opened 4 years ago Closed 4 years ago

Categories

(support.mozilla.org :: General, defect)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: princevikayn, Assigned: tasos)

References

()

Details

(Keywords: reporter-external, sec-low, wsec-xss, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Attachments

(2 files)

I would like to report an XSS which occurs in the parameter &country= when saving your profile to be updated.

Steps to reproduce the issue:

  1. Login your profile https://support.mozilla.org/en-US/users/edit

  2. Save your request/profile and you will see the parameters, namelessly the &country= one is what we're looking at.

See screenshot: https://prnt.sc/hKq17BUoh_kh

  1. Inside of the &country= add the following payload &country=\"><svg/onmouseover=alert(document.domain)> and after saving and turning off your browser's proxy, you shall be prompted with an XSS alert.

Here's a video POC attached below.

I understand this is a self XSS, however this is also an unintended behavior.

A small monetary reward may or may not be awarded.

Flags: sec-bounty?

Since the video POC did not upload. I decided to upload it onto my private account.

Hello Kei,

Thank you for your report.

I can confirm the XSS. As you can see in the screenshot, the country parameter is reflected back in the response without encoding which allows the XSS to execute.

I will follow up with the team so that they can look into it.

Thanks,
Frida

Attached image XSS payload is executed
Status: UNCONFIRMED → NEW
Type: task → defect
Component: Other → General
Ever confirmed: true
Product: Websites → support.mozilla.org

Hello Leo, Hello Tasos,

Can you please take a look at this report?

Thanks,
Frida

Flags: needinfo?(tasos)
Flags: needinfo?(lmcardle)
Keywords: sec-low, wsec-xss
Assignee: nobody → tasos
Flags: needinfo?(tasos)
Flags: needinfo?(lmcardle)

Hello,

Any updates on the bug bounty payment?

Hello Kei,

We usually discuss payments when the issue is fixed.

Thanks,
Frida

(In reply to Frida Kiriakos [:frida] from comment #7)

Hello Kei,

We usually discuss payments when the issue is fixed.

Thanks,
Frida

Got it.

Thank you.

Hello, any updates in regards to this?

Hello Kei,

The bug is assigned to the engineering team so they are aware of the bug and are working on it. We will post updates to the bug when we have more information.

Thanks,
Frida

(In reply to Tasos Katsoulas [:tasos] from comment #11)

PR https://github.com/mozilla/kitsune/pull/5092

Awesome.

This is great news.

How do I go about getting a bounty?

Hello Kei,

When the fix is deployed and the bug is resolved as FIXED, we have a bug bounty panel that meets every week (unless there is a holiday) to decide on bug bounties. So we will update this bug when we a decision about the bounty.

Thanks,
Frida

Status: NEW → ASSIGNED

Hello,

It's been a week now. Any updates on the payment?

Please refer to comment 13. We are waiting for the bug to be fixed in order to discuss the bounty.

The issue is fixed on staging, I will leave the bug open until changes are deployed to production.

The fix has been released to prod.

Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED

Hello,

Updates on this again.

I can confirm the fix on production.

Thanks very much for reporting this issue to us. Now that the issue is fixed, the bug bounty team will be reviewing your report over the upcoming weeks to decide on the award (if any) Mozilla will be granting for this report. It may take up to 3 weeks but know that we've not forgotten this ticket, we have a tracking system and a review cadence that will ensure that all potentially bounty eligible reports get reviewed and acted on.

Unfortunately self-XSS are excluded from our bounty program.

Flags: sec-bounty? → sec-bounty-
Group: websites-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: