Just got emails sent to security@tools.wmflabs.org, admin@, webmaster@, and abuse@ regarding https://www.openbugbounty.org/reports/1022554/
It sounds like someone needs to contact the researcher, ROOTxDEAD aka Sohail Shaikh on sohailss799@gmail.com (email is public at https://www.openbugbounty.org/researchers/ROOTxDEAD/) to get actionable details.
Hello
Security Team,
Sorry for the late reply this email was marked as spammed. I found a vulnerability on your website regarding Cross Site Scripting.
About the Vulnerability
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.
{ https://tools.wmflabs.org/ }
Vulnerable link:-
https://tools.wmflabs.org/not-in-the-other-language/?lang1=de&proj1=wi ki&lang2=en&proj2=wiki&cat=&depth=9&starts_with=&pagepile='><svG onLoad=prompt(9)>
1. Go on this URL
https://tools.wmflabs.org/not-in-the-other-language/?lang1=de&proj1=wi ki&lang2=en&proj2=wiki&cat=&depth=9&starts_with=&pagepile=
2. Then after pagepile=
3. Paste this script '><svG onLoad=prompt(9)>
4. Hit enter and you will get a pop up of Cross Site Scripting
Thanks & Regards
