Cross site scripting in type parameter

Disclosed: 2014-08-07 18:51:15 By knightsword To uzbey
Unknown
Vulnerability Details
https://staging.uzbey.com/crop-image?fid=1996&type=%22%3E%3Cscript%3Ealert%281%29%3C/script%3E click the above url and you can able to view the pop up
Actions
View on HackerOne
Report Stats
  • Report ID: 17299
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report