Blind stored XSS on from https://talent.indeed.com to http://auscorp-analyticstest1.indeed.net:8012/notebooks/8221

Disclosed by
bigBugGuy's avatar
bigBugGuy
  • Engagement Indeed
  • Disclosed date almost 3 years ago
  • Points 5
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by bigBugGuy

I plan on making a video on blind XSS. I'd like to include a few real world examples. Among those included will be an example that features Google, a company that has given me permission to include. I'd like to include this submission as well.

Activity
  1. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  2. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  3. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  4. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  5. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  6. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  7. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()Edited

  8. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  9. Kyle_indeed’s avatar
    Kyle_indeed Customer published the disclosure report

    ()

  10. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  11. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  12. bigBugGuy’s avatar
    bigBugGuy resolved a blocker for Indeed by responding to comments

    ()

  13. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  14. cliff_bugcrowd’s avatarbugcrowd logo
    cliff_bugcrowd sent a message

    ()

  15. cliff_bugcrowd’s avatarbugcrowd logo
    cliff_bugcrowd created a blocker on the researcher to respond to comments

    ()

  16. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  17. flerken’s avatar
    flerken Customer sent a message

    ()

  18. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  19. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  20. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  21. bigBugGuy’s avatar
    bigBugGuy requested disclosure

    ()

  22. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  23. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  24. Kyle_indeed’s avatar
    Kyle_indeed Customer sent a message

    ()

  25. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  26. Richard_Bugcrowd-Product’s avatarbugcrowd logo
    Richard_Bugcrowd-Product changed the state to Duplicate

    ()

  27. Richard_Bugcrowd-Product’s avatarbugcrowd logo
    Richard_Bugcrowd-Product changed the state to Not applicable

    ()

  28. trim_bugcrowd (deactivated)’s avatar
    trim_bugcrowd (deactivated) Customer sent a message

    ()

  29. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  30. trim_bugcrowd (deactivated)’s avatar
    trim_bugcrowd (deactivated) Customer sent a message

    ()

  31. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  32. trim_bugcrowd (deactivated)’s avatar
    trim_bugcrowd (deactivated) Customer sent a message

    ()

  33. trim_bugcrowd (deactivated)’s avatar
    trim_bugcrowd (deactivated) Customer changed the state to Duplicate

    ()

  34. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  35. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  36. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  37. bigBugGuy’s avatar
    bigBugGuy created the submission

    ()