Invitation tokens leak to Google Analytics
Low
H
HackerOne
Submitted None
Actions:
Reported by
h33tjev
Vulnerability Details
Technical details and impact analysis
Hi,
While testing i have noticed that , the hackerone invitation token gets exposed to google-anaytics.com
How?
Here look at the photo-
████████
We can see that the request payload is exposing the invitation token and its not filtered like this one-
███████
And this is what google does with their request payload-
███████
So that means h1 is giving away invitation tokens to third party apps and letting them store it.
If i missed something ask me before closing the report
And requesting you to check this report- #237201
That report is about exposing private programs with valid POC
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure