godaddy

2 articles
sort: new top best
clear filter
0 8/10

A researcher discovered a blind XSS vulnerability in GoDaddy's internal customer support panel by injecting XSS payloads into user profile fields (first/last name), which executed when support agents accessed the CRM system. The vulnerability allowed arbitrary actions on customer accounts including domain transfers and account deletion, demonstrating how data poisoning can compromise backend systems drawing from shared data stores.

GoDaddy XSS Hunter Cobalt BeEF crm.int.godaddy.com sso.godaddy.com
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 4/10

A reflected XSS vulnerability was discovered in GoDaddy's parked domains redirector processor (mcc.godaddy.com) that could be exploited via URL parameter injection to execute arbitrary JavaScript and steal cookies. The vulnerability has been patched and the researchers rewarded.

GoDaddy mcc.godaddy.com Mohamed A. Baset Seekurity Sonarify
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details