Loading HuntDB...

SQL injection in 3rd party software Anomali

High
U
Uber
Submitted None

Team Summary

Official summary from Uber

SQLi in Anomali from Threatstream on `ts02.uberinternal.com` -- the server was hosted outside of our infrastructure and any potential data exposure was limited to Uber employees, not Uber users. It was a pleasure working with @kazan71p and we look forward to more reports in the future.

Reported by kazan71p

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2500.00

Submitted

Weakness

SQL Injection