[XSS] sandbox.veris.in

Disclosed: 2016-09-09 15:17:42 By bogdantcaciuc To veris
Unknown
Vulnerability Details
Hello I want to report a XSS in ,,Badge Types'' Steps to reproduce : 1. Create a badge with badge name "><img src=x onerror=alert(1)> badge description "><img src=x onerror=alert(1)> , select Organization press ,,Add New Badge Key '' in Key display name complete this with same payload "><img src=x onerror=alert(1)> , complete all requirements but in ,,Input type'' select Text only'' and Confirm badge Type. 2. Press view badge and alert was executed I make video if must
Actions
View on HackerOne
Report Stats
  • Report ID: 137119
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report