Blind XSS in mapbox.com/contact
M
Mapbox
Submitted None
Team Summary
Official summary from Mapbox
@sahilsaif reported a stored blind XSS issue on www.mapbox.com/contact. To fix the issue we escaped user provided message content before sending to our middleware server.
Actions:
Reported by
ehsahil
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$750.00
Submitted
Weakness
Cross-site Scripting (XSS) - Generic