Reflected XSS in the website search

V

by Marcel

Website
hvezdarnacb.cz
Company
České Budějovice Observatory
Vulnerability
Reflected XSS
Status
not fixed

A reflected XSS in the search form of the observatory's websites.

Description

The search form returns the search term back into the page without encoding it. A crafted link can therefore run an attacker's JavaScript in the visitor's browser, as if it came from the observatory's own site. Affected: hvezdarnacb.cz, planetky.cz, klet.cz, klet.org and komety.cz.

Details

"><script>alert('reflected')</script><img src=x style=display:none onerror=null alt="

Reflected XSS triggered via the search field

What a real, invisible attack could look like is shown in the deep dive on this finding.

Disclosure Timeline

17 November 2024  - vulnerability reported24 August 2025    - follow-up report resent9 June 2026       - follow-up report resent30 September 2026 - phone call with the IT department; a fix is not planned at this time