[github.algolia.com] XSS
A
Algolia
Submitted None
Actions:
Reported by
bogdantcaciuc
Vulnerability Details
Technical details and impact analysis
Hello , i found a Cross-Site-Scripting in your github subdomain.
All you have to do is to search in this input ( i attached input.PNG )
Search about ,,document domain''
Alert was executed , because you don't sanitize the query which comes from github
Search about ,,svg onload'' -> github.algolia.com
Thanks.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic