robbraxman / braxme

Brax.Me - Privacy Focused Social Media - Fully operational platform

Home Page:https://brax.me

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

status.php xss bug

fd1f opened this issue · comments

there is a weird thing on status.php, i'm not the one who found it. for example, you could go to
https://brax.me/prod/status.php?a=<script>alert('hello');document.body.innerText = "world"</script>
and it would run the javascript without a care.

Thank you. It was a test file. It is not used. It has been deleted. Appreciated!

File deleted