Description
Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Name Profile input. Attackers can inject malicious script code through a POST request that executes on application review without user interaction.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
8.0.0
Credits
TaurusOmar
References
www.vulnerability-lab.com/get_content.php?id=2315 (Vulnerability Lab Advisory)
apps.apple.com/ec/app/banco-guayaquil/id624963066 (Product Homepage)
www.vulncheck.com/...s-site-scripting-via-profile-name-input (VulnCheck Advisory: Banco Guayaquil 8.0.0 Mobile iOS Cross-Site Scripting via Profile Name Input)