Interactive YouTube API Demo Beta Vulnerable to XSS(Cross Site Scripting)

Some white hat hacker named as "Vansh Sharma" discovered the XSS vulnerability in Interactive YouTube API Demo Beta .

The keyword field is vulnerable to XSS .

  • Open
  • Enter script
    <img src="<img src=search"/onerror=alert("xss")//">
    in the keyword area.
  • Press ADD
Vulnerability Status:
  • Type: XSS
  • organization:
  • Status: UnFixed
