dom-based

2 articles
sort: new top best
clear filter
0 7/10

A researcher discovered a stored blind XSS vulnerability in GoDaddy's internal customer support CRM panel by injecting malicious payloads into first/last name fields that triggered when support agents accessed customer accounts, allowing potential session hijacking and account manipulation. The vulnerability was reported through GoDaddy's bug bounty program, marked as a known duplicate, and remediated through input filtering rather than output encoding.

GoDaddy XSS Hunter BeEF Cobalt crm.int.godaddy.com sso.godaddy.com
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 10 hours ago · details
0 6/10
bug-bounty

A bug bounty writeup covering three reflected XSS vulnerabilities discovered on a Synack program: one via JavaScript protocol in a referrer header parameter, one via password-check parameter bypass in account details modification, and one via insufficient input filtering in an email recovery parameter.

Gaurav Narwani Synack burp
gauravnarwani.com · devanshbatham/Awesome-Bugbounty-Writeups · 10 hours ago · details