SQL injection in 3rd party software Anomali
High
U
Uber
Submitted None
Team Summary
Official summary from Uber
SQLi in Anomali from Threatstream on `ts02.uberinternal.com` -- the server was hosted outside of our infrastructure and any potential data exposure was limited to Uber employees, not Uber users. It was a pleasure working with @kazan71p and we look forward to more reports in the future.
Actions:
Reported by
kazan71p
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2500.00
Submitted
Weakness
SQL Injection