> For the complete documentation index, see [llms.txt](https://strange-1.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://strange-1.gitbook.io/notes/security-blogs/bug-hunting/xss/blog-site-search-field.md).

# Blog site search field

### Summary:

The blog site is vulnerable to reflected XSS in the search parameter. This vulnerability allows attackers to inject malicious scripts into the search query, which are then reflected back to users when they perform a search.

### Steps To Reproduce:

1. Go to `https://blog.example.com/?s=<A HREF=https://attacker.com/>XSS-BY-STRANGE</A>` Or Enter the payload manually in search box.
2. Payload Used :

```
 <A HREF=https://attacker.com/>XSS-BY-STRANGE</A>
```

### Screenshots

<figure><img src="https://2161260008-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLrlKEAjeD4GG1UeUPxlB%2Fuploads%2FzTDq5dfZIVHHSmsUAHZs%2F1.jpg?alt=media&amp;token=e694eb78-904e-4144-a48b-5e6d6e9c2c74" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2161260008-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLrlKEAjeD4GG1UeUPxlB%2Fuploads%2FGZwrBWkj1Ib7t7UpsoCp%2F2.png?alt=media&amp;token=d7714b44-68f1-4c80-832e-f4ec93ee684d" alt=""><figcaption></figcaption></figure>

### Impact

The presence of reflected XSS on the blog site introduces significant security risks. Attackers can craft malicious search queries containing scripts that, when executed, can steal user credentials, perform unauthorized actions on behalf of the user, or redirect them to malicious websites. Immediate attention is required to address this vulnerability and protect users from potential harm.
