Content spoofing via parameters url, w, and q (unauthenticated and wallet-connected)
The url, w, and q query parameters were reflected into rendered page content without sufficient encoding, enabling content spoofing variants of reflected XSS in both unauthenticated and authenticated (wallet-connected) states.
Description
The application reflected user-controlled values from the url, w, and q query parameters into page content rendered to the user. Both unauthenticated and wallet-connected states were affected. While script execution was not demonstrated as part of this report, attacker-controlled text rendered into the page enabled content spoofing (text-level phishing or impersonation) and provided an injection primitive that could compound with other rendering bugs.
Impact
- Phishing-friendly content placed inside the trusted origin via crafted links.
- Loss of UI integrity when an attacker can choose what users see at specific URLs.
- Foundation for full reflected XSS if any consumer ever rendered the reflected value as HTML.
Recommendation
HTML-encode all reflected parameter values before including them in page content. Where the parameter is expected to be a known URL or token, validate against an allowlist and reject unknown content rather than reflecting it.
All Your Base: Acknowledged. Zealynx: Acknowledged.