Loading HuntDB...

Non Critical Code Quality Bug / Self XSS on Map Editor

Medium
I
Infogram
Submitted None
Reported by mksecurity

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
Hi Team, I've found non-critical XSS on map editor. It is not for bounty just for code quality. This is my url: https://infogram.com/app/#edit/c024c717-31c2-4c31-8491-1cc9534e9adb When i added map on form then edit Country name and replace with "<script>alert(1);</script>" it is executed. Attached screenshots.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored