[XSS] sandbox.veris.in
Unknown
Vulnerability Details
Hello I want to report a XSS in ,,Badge Types''
Steps to reproduce :
1. Create a badge with badge name "><img src=x onerror=alert(1)> badge description "><img src=x onerror=alert(1)> , select Organization press ,,Add New Badge Key '' in Key display name complete this with same payload "><img src=x onerror=alert(1)> , complete all
requirements but in ,,Input type'' select Text only'' and Confirm badge Type.
2. Press view badge and alert was executed
I make video if must
Actions
View on HackerOneReport Stats
- Report ID: 137119
- State: Closed
- Substate: resolved
- Upvotes: 5