Cross-site Scripting (XSS) - Reflected in alovoa/alovoa

Valid

Reported on

Jul 19th 2021


✍️ Description

xss bug

🕵️‍♂️ Proof of Concept

1. Open url https://alovoa.com/profile?lang=es%22%3E%3Cscript%3Ealert(1)%3C/script%3E and see xss is executed .
My previous xss and this xss has different attacking endpoint and thats why i submitted two report

💥 Impact

xss

We have contacted a member of the alovoa team and are waiting to hear back a year ago
ranjit-git modified the report
a year ago
Nho Quy Dinh validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Nho Quy Dinh marked this as fixed with commit 3c93de a year ago
Nho Quy Dinh has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation