wowthemesnet / mundana-theme-jekyll

Mundana is a free Jekyll theme, Medium styled.
https://wowthemesnet.github.io/mundana-theme-jekyll/
747 stars 803 forks source link

XSS in homepage search bar #33

Open bugdisclose opened 4 years ago

bugdisclose commented 4 years ago

the search bar is vulnerable to the XSS Simply inject the "><img src=1 onerror=alert(document.cookie)> you'll see the reflected xss is there.