[-] Exploit Title: Gap Messenger Reflected Cross-Site Scripting
[-] Vendor Homepage: https://gap.im/en/
[-] Author: Milad Ahmadi
[-] Email: info@securityhub.ir
[-] Date : 2018-04-22
[-] Tested on Windows 10
[ Description]
# Gap Messenger is free cloud-based messenger with multi-device capability. this messenger is vulnerable to reflected cross-site scripting vulnerability.
# to exploit this vulnerability edit your profile and change name field to some javascript code like "myname<script>alert(1)</script>" then visit your profile in your browser.
[ Vulnerable URL ]
# https://gap.im/[ USER_ID ]
Twitter: @securityhubir
Virgool : @securityhub