Stored XSS
I
Instacart
Submitted None
Actions:
Reported by
s44mux
Vulnerability Details
Technical details and impact analysis
First log in account.
We headed to the "lists and recipes" option
https://www.instacart.com/store/demo/lists
create a new list "add list"
Payload
"></script></title><script>alert(document.domain)</script>
URL pwned.
https://www.instacart.com/lists/izy0w6Q?preview=true
attached a screenshot
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic