docpad-archive / docpad-skeleton-nodechat

Node Chat, built using Socket.io, DocPad, Backbone.js and Twitter Bootstrap

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

XSS on User field

DinisCruz-QA opened this issue · comments

Cross-site-Scripting payloads can be placed on the username field:

payload inserted:
image

payload executed (after payload inserted):
image

payload executed (on victim's browser
image

for reference see: