Critical Stored XSS on

The vulnerability is located in the real name parameter during registration. During registration, attackers could insert malicious payloads into the ‘real name’ parameter. Basically, every page that the name of the attacker account gets printed will execute the malicious code. It can also be use with XSRF to further exploit the vulnerability.
This vulnerability is reported on 10 November 2012 and fixed on 24 November 2012.
The bug fixing process went very smoothly, thanks to the great engineer team!



