Cross-site Scripting (XSS) - Reflected in alovoa/alovoa

Valid
Reported on Jul 19th 2021

✍️ Description

xss bug

🕵️‍♂️ Proof of Concept

1. Open url https://alovoa.com/profile?lang=es%22%3E%3Cscript%3Ealert(1)%3C/script%3E and see xss is executed .
My previous xss and this xss has different attacking endpoint and thats why i submitted two report

💥 Impact

xss

We have contacted a member of the alovoa team and are waiting to hear back 7 days ago
ranjit-git modified their report
7 days ago
Nho Quy Dinh validated this vulnerability 7 days ago
ranjit-git has been awarded the disclosure bounty
$25
The fix bounty is now up for grabs
$6.25
Nho Quy Dinh confirmed that a fix has been merged on 3c93de 7 days ago
Nho Quy Dinh has been awarded the fix bounty
$6.25