Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0002·content-spoofing

Content spoofing via parameters url, w, and q (unauthenticated and wallet-connected)

Acknowledgedpentestblackboxnestjs
TL;DR

The url, w, and q query parameters were reflected into rendered page content without sufficient encoding, enabling content spoofing variants of reflected XSS in both unauthenticated and authenticated (wallet-connected) states.

Severity
MEDIUM
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

The application reflected user-controlled values from the url, w, and q query parameters into page content rendered to the user. Both unauthenticated and wallet-connected states were affected. While script execution was not demonstrated as part of this report, attacker-controlled text rendered into the page enabled content spoofing (text-level phishing or impersonation) and provided an injection primitive that could compound with other rendering bugs.

03Section · Impact

Impact

  • Phishing-friendly content placed inside the trusted origin via crafted links.
  • Loss of UI integrity when an attacker can choose what users see at specific URLs.
  • Foundation for full reflected XSS if any consumer ever rendered the reflected value as HTML.
04Section · Recommendation

Recommendation

HTML-encode all reflected parameter values before including them in page content. Where the parameter is expected to be a known URL or token, validate against an allowlist and reject unknown content rather than reflecting it.

All Your Base: Acknowledged. Zealynx: Acknowledged.

F-2024-0002