XSS vulnerability in "/coach/roster/" ( create your first class)

Disclosed: 2016-02-12 18:57:51 By hacker00000000 To khanacademy
Unknown
Vulnerability Details
Hi Security Team , Today I found xss vulnerability in "/coach/roster/" ( create your first class) steps : - Go to " Manage students " - click in " create your first class " - create your first class Title name ===> "><img src=x onerror=prompt(0);> - click "create class " Good Fix ,
Actions
View on HackerOne
Report Stats
  • Report ID: 111763
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report