Loading HuntDB...

Stored xss

A
Algolia
Submitted None
Reported by rishi62

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hi,i have found an stored xss which is reflected at https://www.algolia.com/explorer#?index=getstarted_actors&tab=explorer Steps to produce: 1) Go to https://www.algolia.com/explorer#?index=getstarted_actors&tab=explorer and add "><img src=x onerror=alert(document.cookie);> as an attribute and keep it at top as in screenshot1 2) Go to https://www.algolia.com/explorer#?index=getstarted_actors&tab=ranking and take the cursor on the ranking info(the trophy icon),and you will see a pop up alert of xss. (Screenshot2) I have tested it on Chrome and firefox its works on both. P.S: I dont know why but my ip got banned when i was uploading the script to test could you unban me?

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic