callback-parameter

1 article
sort: new top best
clear filter
0 7/10

Researcher discovered a stored XSS vulnerability in Uber's invitation link feature by injecting a payload into the 'v' parameter, then bypassed the strict Content Security Policy by leveraging the whitelisted *.uber.com domain to load a malicious Marketo callback endpoint, resulting in a $2,000 bounty.

Uber partners.uber.com mkto.uber.com Marketo stamone Efkan HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details