Persistent class XSS [the fuck]

Disclosed: 2014-04-09 17:06:03 By smiegles To khanacademy
Unknown
Vulnerability Details
Hi, I created a class called : `</script>"><img src=x onerror=alert(0)>` and it actually worked 0.0. It worked here for me : https://www.khanacademy.org/coach/reports/grid?force=1 Best regards, Olivier Beg
Actions
View on HackerOne
Report Stats
  • Report ID: 6412
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report