Cross-site Scripting (XSS) - Reflected in alovoa/alovoa

Reported on Jul 19th 2021

✍️ Description

xss bug

🕵️‍♂️ Proof of Concept

1. Open url and see xss is executed .
My previous xss and this xss has different attacking endpoint and thats why i submitted two report

💥 Impact


We have contacted a member of the alovoa team and are waiting to hear back 7 days ago
ranjit-git modified their report
7 days ago
Nho Quy Dinh validated this vulnerability 7 days ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Nho Quy Dinh confirmed that a fix has been merged on 3c93de 7 days ago
Nho Quy Dinh has been awarded the fix bounty