Stored XSS in name selection

Disclosed: 2016-06-18 18:26:15 By daveysec To algolia
Unknown
Vulnerability Details
You have a stored XSS vuln when you set your name in your account information. to reproduce just set your name field to: </script><script>alert('xss')</script> and most pages on your account you will show XSS.
Actions
View on HackerOne
Report Stats
  • Report ID: 102755
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report