Please fix the xss vulnerability quickly

Sort:
Avatar of Saintliy

I already knew about this and reported it several times, but it still hasn't been fixed and there are even people who are abusing it.

I won't tell people how to do it publicly, but if you're an admin I'll give you the code.

Avatar of Jordi_Agost

Wow, seriusly ?

Avatar of Martin_Stahl

https://support.chess.com/en/articles/8704800-is-there-a-bug-bounty-can-i-get-paid-for-finding-bugs

Avatar of plux

I have a question re: bug bounties from chess.com.... Since i'm certain it is against chess.com terms of service to actively try to hack the website, is there a chess.com test server or something equivalent to that where it would be permissible to try to break things??

I'm, uh... *cough, cough*... asking for a friend...

Avatar of Martin_Stahl
plux wrote:

I have a question re: bug bounties from chess.com.... Since i'm certain it is against chess.com terms of service to actively try to hack the website, is there a chess.com test server or something equivalent to that where it would be permissible to try to break things??

I'm, uh... *cough, cough*... asking for a friend...

Not that I'm aware of and the above bug bounty link should have the information on what is allowed. Doing anything that would break the site, or portions, is prohibited by the TOS