data-deletion

1 article
sort: new top best
clear filter
0 5/10

Clickjacking vulnerability on Google Custom Search Engine (CSE) settings page allows attackers to trick users into deleting their CSE instances through UI redressing by overlaying fake buttons on an embedded iframe. Google rejected the finding as not severe enough despite the ability to delete user data.

Google CSE cse.google.com Akbar Kustirama
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details