XSS in the input

Disclosed: 2014-07-08 10:00:33 By stocktonontees To respondly
Unknown
Vulnerability Details
https://app.respond.ly/create once there go to Team Name and input the code ?'"--></style></script><script>alert(1337)</script> and put the email as a valid one and should inject the XSS code even should show when u login all the time. Thanks, Jordan Jones @CEHSecurity
Actions
View on HackerOne
Report Stats
  • Report ID: 12389
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report