GraphJet
GraphJet copied to clipboard
Reflective xss
hi:
I found a reflective xss vulnerability in the GetSimilarHashtagsServlet.java
Details are as follows:
The "hashtag" parameter in the get request is received at line 38 of the file.
Without any filtering, the output directly on line 58 caused the xss vulnerability on the page.