A security researcher "Fabián Cuchiett" have discovered XSS vulnerability in the official website of Harvard university. Sub domain of Harvard univ , leverett.harvard.edu vulnerable to XSS attack.
Few days back, longrifle0x discovered XSS vulnerability in www.college.harvard.edu website. It seems that website admin don't care about the security of their website and left lot of vulnerability.
Poc:
http://leverett.harvard.edu/reservations/index.php?Day=%3Cscript%3Ealert%28%27@FabianCuchietti%27%29%3C/Script%3E