Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
You're correct. However, that's a problem every programmer has to face. There's a programming principle that you should always make sure data is sanitized before displaying/processing it. That responsibility falls in the hands of the developers, because only they know the context in which the data is going to be used. We do appreciate you taking the time to write your reports, but only reports that are about vulnerabilities in Facebook products and qualifying acquisitions. Please follow up with any security vulnerabilities you find.
In these cases, the third-party app developers are responsible for properly escaping data from the Instagram API. You may want to contact the app developers, but you are correct that we do not consider this a vulnerability in Instagram
XSS на сайтах, использующих Instagram API