Cookie-Based Cross-Site Scripting (XSS)


This vulnerability counts as medium risk. All you need is install Cookies Manager+ addon in firefox or any other addon/plugin that use to manipulate cookie.

Browse the page as usual.


Open Cookies Manager+ and search for vulnerable cookie parameter, in this case is C_UL parameter. Double click on it and change the content with XSS payload and Save it.





Back to the browser, refresh the page and you will see the pop-up.



Thats it! This kind of vulnerability worth 50-100 usd in bug bounty program. Happy hunting! :)