bhamrick / multitwitch

Multiple twitch streams on one page
575 stars 147 forks source link

multitwitch.tv xss #32

Closed tarun776 closed 5 years ago

tarun776 commented 5 years ago

Hi twitch.tv security team

My name is Tarun Mahour from india

The bug is Reflected Cross site Scripting

The doamin is www.multitwitch.tv

Vulnerable url http://www.multitwitch.tv/hack"-alert(document.domain)-"

xss payload hack"-alert(document.domain)-"

I hope you will fix it ASAP

And Please provide reward and certificate

Thanks for reading

bhamrick commented 5 years ago

Hi!

Thank you for your report. I've made some changes so this should be mitigated. Please let me know if you notice any other issues in the future.

Unfortunately, I am not affiliated with twitch.tv in any way, and I cannot offer any reward other than my gratitude.