mirror of
https://github.com/benbusby/whoogle-search.git
synced 2026-04-25 20:25:51 +03:00
[GH-ISSUE #1076] Whoogle XSS #654
Labels
No labels
Fixed (Pending PR Merge)
Stale
bug
enhancement
enhancement
good first issue
help wanted
keep-open
needs more info
pull-request
question
theme
unfortunate
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/whoogle-search#654
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @0xspade on GitHub (Oct 6, 2023).
Original GitHub issue: https://github.com/benbusby/whoogle-search/issues/1076
Describe the bug
Whoogle current version is vulnerable to XSS, if the result has an xss payload
<iframe srcdoc="<script>alert('XSS - 13')</script>"></iframe >, it will trigger the xss.To Reproduce
Steps to reproduce the behavior:
iframe srcdoc xssDeployment Method
runexecutableVersion of Whoogle Search