Stored xss
A
Algolia
Submitted None
Actions:
Reported by
rishi62
Vulnerability Details
Technical details and impact analysis
Hi,i have found an stored xss which is reflected at https://www.algolia.com/explorer#?index=getstarted_actors&tab=explorer
Steps to produce:
1) Go to https://www.algolia.com/explorer#?index=getstarted_actors&tab=explorer and add "><img src=x onerror=alert(document.cookie);> as an attribute and keep it at top as in screenshot1
2) Go to https://www.algolia.com/explorer#?index=getstarted_actors&tab=ranking and take the cursor on the ranking info(the trophy icon),and you will see a pop up alert of xss. (Screenshot2)
I have tested it on Chrome and firefox its works on both.
P.S: I dont know why but my ip got banned when i was uploading the script to test could you unban me?
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic