Friday, June 17, 2016

FormZero.in - SQL Injection & XSS Vulnerable

XSS Vulnerability in formzero.in

This is a POC formzero.in - POC - SQL Injection (Fixed) & XSS (Not Fixed)

 
In last few months I discovered and reported a lot of bugs on a lot of different websites. Last month I posted about the askmebazaar.com bug and now this month I am sharing my experience with formzero.in. An Indian company which provides easy to use online form system (similar to Google Forms) to institutes, universities, companies and schools.