Reflected XSS on Partners Subdomain
High
U
Uber
Submitted None
Team Summary
Official summary from Uber
There was a reflected cross site scripting vulnerability at https://partners.uber.com/. By providing a specifically crafted value, it was possible for an attacker to inject malicious content into the partners.uber.com site, which would then be executed when the site is loaded. We enjoyed working with @mefkan on this issue and look forward to their next submission to our program.
Actions:
Reported by
mefkan
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2000.00