xss filter bypass [polldaddy]

Disclosed: 2017-10-01 15:56:17 By paresh_parmar To automattic
Unknown
Vulnerability Details
Hi, previously reported xss https://hackerone.com/reports/107405 which is fixed, but i am able to bypass that fix. Payload for bypass : `<a href="javascript&colon;alert&lpar;document&period;domain&rpar;">Click Here</a>` # Steps: - Login into Polldaddy account polldaddy.com - go to ___POLLS___ and create new poll - in answers. enter xss payload `<a href="javascript&colon;alert&lpar;document&period;domain&rpar;">Click Here</a>` {F217173} - Save it - go here :where you can edit style https://polldaddy.com/polls/XXXXX/style-edit/ {F217170} scroll down and click on it , xss will trigger. {F217172} Ref: https://hackerone.com/reports/107405 Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 264832
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report