the XSS was working till the time this article was posted.

although Facebook will correct it soon.

XSS enables attackers to inject client-side script into Web pages viewed by other users.

Article image

A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same origin policy.

(source:wiki).

Article image

spot_img

source: www.techworm.net