Loading HuntDB...

Stored XSS in albums on http://m.imgur.com/

I
Imgur
Submitted None

Team Summary

Official summary from Imgur

Special characters were not being escaped on the mobile web product properly. This allowed an attacker to set a description or title to an XSS payload which would then execute upon loading.

Reported by strukt

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic