Loading HuntDB...

DOM XSS on duckduckgo.com search

Medium
D
DuckDuckGo
Submitted None
Reported by cujanovic

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Reflected
Hello, The is a DOM XSS vulnerability on https://duckduckgo.com search through the `relsexp` parameter. PoC URL: ` https://duckduckgo.com/?q=a&relsexp="><img src=/ onerror=alert(document.domain)>&ia=web` Screenshot: {F830875} Video: {F830880} ## Impact The attacker can execute JS code.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected