xss filter bypass [polldaddy]
Unknown
Vulnerability Details
Hi,
previously reported xss https://hackerone.com/reports/107405 which is fixed, but i am able to bypass that fix.
Payload for bypass : `<a href="javascript:alert(document.domain)">Click Here</a>`
# Steps:
- Login into Polldaddy account polldaddy.com
- go to ___POLLS___ and create new poll
- in answers. enter xss payload `<a href="javascript:alert(document.domain)">Click Here</a>`
{F217173}
- Save it
- go here :where you can edit style https://polldaddy.com/polls/XXXXX/style-edit/
{F217170}
scroll down and click on it , xss will trigger.
{F217172}
Ref: https://hackerone.com/reports/107405
Thanks
Actions
View on HackerOneReport Stats
- Report ID: 264832
- State: Closed
- Substate: resolved
- Upvotes: 21