Hi ,
I Found Blind Stored XSS https://id.wikipedia.org/
Follow me :)
Steps :
- Login your account here https://commons.wikimedia.org/
- Then upload the Image File here https://commons.wikimedia.org/wiki/Special:UploadWizard
- If you have, click "Continue"
- Then you will find the features:
This site requires you to provide copyright information for this work, to make sure everyone can legally reuse it.
This file is my own work.
This file is not my own work.
- Select "This file is not my own work."
- XSS is in the input form "Source & Author(s)"
- Next, input the XSS payload in the 2 Input Forms :)
Payloads:
"><img src=c onerror=prompt(document.domain)>
- Then if you have, click "Publish File"
- Then you will get the URL:
To use the file in a wiki, copy this text into a page:
[[File:HACKED0001231313123123123131.jpg|thumb|"><img src=c onerror=prompt(document.domain)>]]
To link to it in HTML, copy this URL:
https://commons.wikimedia.org/wiki/File:HACKED0001231313123123123131.jpg
- Next Edit User Article https://id.wikipedia.org/
- Click Insert "Image & Media Tool"
- Input the URL of your PHOTO location that has been inserted XSS :)
https://commons.wikimedia.org/wiki/File:HACKED0001231313123123123131.jpg
- Look, your photo appears
- Then click, and see a pop up appear and XSS is triggered :)
Supporting Report :
- Screenshot
Download Now :
https://www.dropbox.com/s/mlleeemug0znhzf/BLIND%20STORED%20XSS%20WIKIPEDIA.jpg?dl=0
- Video
Download Now :
https://www.dropbox.com/s/b4uge4kgdw3ves6/BLIND%20STORED%20XSS%20WIKIPEDIA%202.mp4?dl=0