Skip to content

One more question #2

Description

@ManShum812

Hi sean,

Sorry to bother u again. I was wondering is there any payload can allow you to change the source code by exploiting the swagger xss vulnerability.

For example:
https://vulnerability.com/content-exploration/swagger-ui/index.html?configURL=https://xss.smarpo.com/test.json
Screenshot (93)

https://non-vulnerability.com/content-exploration/swagger-ui/index.html?configURL=https://xss.smarpo.com/test.json
Screenshot (94)

From here you can see that the page source is pretty much the same from non-vulnerability.com and vulnerability.com.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions