============================================= INTERNET SECURITY AUDITORS ALERT 2013-005 - Original release date: 3rd March 2013 - Last revised: 10th March 2013 - Discovered by: Eduardo Garcia Melia - Severity: 5.2/10 (CVSS Base Scored) ============================================= I. VULNERABILITY ------------------------- LinkedIn social network is affected by Persistent Cross-Site Scripting vulnerability. II. BACKGROUND ------------------------- LinkedIn is a social networking service and website operates the world's largest professional network on the Internet with more than 187 million members in over 200 countries and territories. More Information: http://press.linkedin.com/about III. DESCRIPTION ------------------------- LinkedIn social network is affected by Persistent Cross-Site Scripting vulnerability. The persistent (or stored) XSS vulnerability is a more devastating variant of a cross-site scripting flaw: it occurs when the data provided by the attacker is saved by the server, and then permanently displayed on "normal" pages returned to other users in the course of regular browsing, without proper HTML escaping. The affected resource is http://www.linkedin.com/people/connections when you create new tags. IV. PROOF OF CONCEPT ------------------------- ========================= First Option ========================= You can go to LinkedIn Contacts -> Connections -> Manage. After, on the "Add New Tag" field, you can put these tags, for example: +