forked from postmanlabs/httpbin
-
Notifications
You must be signed in to change notification settings - Fork 28
Open
Description
This implementation is vulnerable to XSS described here https://blog.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/
Reproduction with the following URL /?url=https://jumpy-floor.surge.sh/test.yaml
Metadata
Metadata
Assignees
Labels
No labels