Loading HuntDB...

Reflected XSS on Partners Subdomain

High
U
Uber
Submitted None

Team Summary

Official summary from Uber

There was a reflected cross site scripting vulnerability at https://partners.uber.com/. By providing a specifically crafted value, it was possible for an attacker to inject malicious content into the partners.uber.com site, which would then be executed when the site is loaded. We enjoyed working with @mefkan on this issue and look forward to their next submission to our program.

Reported by mefkan

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2000.00

Submitted