developer-portal

1 article
sort: new top best
clear filter
0 2/10

A beginner bug bounty hunter discovered a Self-XSS vulnerability in Amazon's developer.amazon.com where Security Profile names were reflected in source code, which they escalated to a logout CSRF issue. The vulnerability was reported, triaged, and fixed within a week, though no monetary reward was offered per Amazon's policy.

Amazon developer.amazon.com Coding_Karma Karel_Origin Robert Smith
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details