HomeSecurityAN0NT0XIC: XSS vulnerability identified in the Ministry of Health

AN0NT0XIC: XSS vulnerability identified in the Ministry of Health

moh.gov.gr-min

An XSS vulnerability was discovered by a young Greek hacker with the nickname "AN0NT0XIC" , on the Ministry of Health website.

According to an email update that the SecNews editorial team received from “AN0NT0XIC”, he identified the XSS vulnerability that allows a message to be displayed in the visitor’s browser with appropriately modified requests on the search page [see here]. We present the relevant Screenshot that indicates the existence of the vulnerability, as sent to us by the young hacker:

AN0NT0XIC

The exact link to the existence of the vulnerability is known to the editorial team, has been confirmed but is NOT made public for obvious reasons.

According to what the young man, who has a degree in IT and has been actively involved in Pentesting since a young age, says, his goal is to remain a whitehat and indicate to the general public that there are weaknesses even in the most important networks that need to be fixed. He also states in his email that he “does not belong to any group, despite all the proposals he has accepted to join some of them.”

It is certainly extremely optimistic to see young people involved in pentesting, vulnerability research and network security from a very young age. Of course, it is worth noting that when the attempt to identify vulnerabilities is carried out without informing the person being tested, criminal problems may arise, so it is advisable to avoid this. However, a coordinated state must take advantage of the extremely large number of young people involved in this sector, in order to strengthen the security of critical infrastructure.

As is well known, XSS vulnerabilities do not easily lead directly to website corruption or server access, but they can be used indirectly to corrupt content at the user-session level. On websites with a large number of users where Phishing can result in visitor redirection, they must be taken seriously and repaired immediately.

SecNews thanks "AN0NT0XIC" for the valid and timely information.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS