Cookie-Based Cross-Site Scripting (XSS)

Jun 6, 2017


This vulnerability counts as low to medium risk. All you need is install Cookies Manager+ addon in firefox or any other addon/plugin used to manipulate cookie.

Browse the page as usual.

Open Cookies Manager+ and search for vulnerable cookie parameter, in this example is C_UL parameter. Double click on it and change the content with XSS payload and Save it.

Back to the browser, refresh the page and you will see the pop-up.

Thats it! This kind of vulnerability worth 50–100 usd in bug bounty program. Depend on the program.

Happy hacking!

