Cross-site Scripting (XSS) - Reflected in alovoa/alovoa


Reported on

Jul 19th 2021

✍️ Description

xss bug

🕵️‍♂️ Proof of Concept

1. Open url and see xss is executed .
My previous xss and this xss has different attacking endpoint and thats why i submitted two report

💥 Impact


We have contacted a member of the alovoa team and are waiting to hear back 2 years ago
ranjit-git modified the report
2 years ago
Nho Quy Dinh validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Nho Quy Dinh marked this as fixed with commit 3c93de 2 years ago
Nho Quy Dinh has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation