The blackbox-exporter application returns user input in the ‘target’ parameter without sanitization when the ‘debug’ parameter is set to ‘true’. This leads to a XSS vulnerability.
Acknowledgments: Name: Jeremy Choi (Red Hat)
External References: https://docs.google.com/document/d/1S9R6hy4Coz6WqvlygeXVme9sZszeaXxbzg5D1MDdj08/edit#