RXSS at image.hackerone.live via the `url` parameter
Low
H
HackerOne
Submitted None
Actions:
Reported by
todayisnew
Vulnerability Details
Technical details and impact analysis
good day
https://image.hackerone.live:8443/;/;/resource/md/get/url?url=http://oast.pro
is allowing full read ssrf wirh permission can try for aws creds.
-Eric
## Impact
full read ssrf
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.01
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected