Album image XSS

Disclosed: 2014-07-18 20:26:16 By bitquark To uzbey
Unknown
Vulnerability Details
There's an XSS in the album script caused by insufficient escaping of double quotes. PoC: https://staging.uzbey.com/album/image/679/1139%22%3E%3Ch1%3ESurprise!%3Cimg%20src=0%20onerror=%22alert(document.domain)%22%3E
Actions
View on HackerOne
Report Stats
  • Report ID: 17235
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report