css-injection

1 article
sort: new top best
clear filter
0 3/10

A researcher discovered and exploited a subdomain takeover vulnerability on feedback.owncloud.com by identifying an orphaned CNAME record pointing to Fider's infrastructure, registering a Fider account, and claiming the subdomain to demonstrate cookie/IP grabbing via CSS injection. The $200 bounty was awarded despite the researcher's assessment that the vulnerability warranted higher compensation.

ownCloud HackerOne Sublist3r Fider getfider.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details