Loading HuntDB...

Invitation tokens leak to Google Analytics

Low
H
HackerOne
Submitted None
Reported by h33tjev

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hi, While testing i have noticed that , the hackerone invitation token gets exposed to google-anaytics.com How? Here look at the photo- ████████ We can see that the request payload is exposing the invitation token and its not filtered like this one- ███████ And this is what google does with their request payload- ███████ So that means h1 is giving away invitation tokens to third party apps and letting them store it. If i missed something ask me before closing the report And requesting you to check this report- #237201 That report is about exposing private programs with valid POC

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure