New issue
Advanced search Search tips

Issue 645968 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: XSS in TrustPilot.com

Reported by orthonvi...@gmail.com, Sep 12 2016

Issue description

Hello team,


There is a website caled trustpilot.com,which gives the reviews for websites.it is giving reviews to google.com website also,where we can trigger our payload to effect the site internally via trustpilot.

steps to reproduce:

1.go to url:https://www.trustpilot.com/evaluate/www.google.com
2.now insert the payload :
"/><svg/onload=prompt(1)>
"/><img src=x onerror=prompt(1)>   into the "write your review"box.
3.you can see the payload get triggered.
4.whenever a user of google is  clicking the review of that attacker xss gets executed-it is the "STORED XSS"
5.
It would be impossible to get XSS to the frontpage, but it is possible to inject the payload to your internal tools via trustpilot.So this can also effect the google internally


i recently reported this issue to other website which is effected by trustpilot internally,they also confirmed after investigating that this can effect their website internally via trustpilot.I was not able to show my report because it is not yet disclosed yet.
let me know if information is required.thanks!
 
Screenshot (420).png
148 KB View Download
Screenshot (419).png
157 KB View Download
Summary: Security: XSS in TrustPilot.com (was: Security: CRITICAL: XSS(effects internally))
@orthonviper: Have you reported this bug to trustpilot.com?

This is an XSS vulnerability in the website trustpilot.com, not a bug in Chrome or a Google property. I believe the user's argument here is that some user of the TrustPilot feature inside Google could end up running maliciously-injected script in the security context of TrustPilot.com.


Comment 2 by wfh@chromium.org, Sep 12 2016

Status: WontFix (was: Unconfirmed)
This is not an issue with the Chromium browser. If you feel this affects Google properties then please report it via https://goo.gl/vulnz

This bug will automatically be re-restricted after 14 weeks so you should disclose anything before then.
Project Member

Comment 3 by sheriffbot@chromium.org, Dec 20 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment