XSS via Google Drive - https://www.indeed.jobs/career/Profile

Disclosed by
CGuillaume's avatar
CGuillaume
  • Engagement Indeed
  • Disclosed date almost 3 years ago
  • Reward $100
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by CGuillaume

XSS via attachments filenames

Activity
  1. Kyle_indeed’s avatar
    Kyle_indeed Customer published the disclosure report

    ()

  2. CGuillaume’s avatar
    CGuillaume requested disclosure

    ()

  3. Jarvis’s avatar
    Jarvis Customer changed the state to Resolved

    ()

  4. Greg_Caswell’s avatar
    Greg_Caswell Customer rewarded CGuillaume 5 points

    ()

  5. Greg_Caswell’s avatar
    Greg_Caswell Customer changed the state to Unresolved

    ()

  6. Greg_Caswell’s avatar
    Greg_Caswell Customer sent a message

    ()

  7. Greg_Caswell’s avatar
    Greg_Caswell Customer rewarded CGuillaume $100

    ()

  8. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd changed the state to Triaged

    ()

  9. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd changed the severity to P4

    ()

  10. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd sent a message

    ()

  11. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd changed the state to New

    ()

  12. CGuillaume’s avatar
    CGuillaume sent a message

    ()

  13. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd changed the state to Won’t fix

    ()

  14. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd updated VRT to Cross-Site Scripting (XSS) > Reflected > Self

    ()

  15. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd sent a message

    ()

  16. CGuillaume’s avatar
    CGuillaume resolved a blocker for Indeed by providing information

    ()

  17. CGuillaume’s avatar
    CGuillaume sent a message

    ()

  18. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd created a blocker on the researcher to provide information

    ()

  19. dax_bugcrowd’s avatarbugcrowd logo
    dax_bugcrowd sent a message

    ()

  20. CGuillaume’s avatar
    CGuillaume created the submission

    ()