google-apps

1 article
sort: new top best
clear filter
0 7/10

A reflected XSS vulnerability was discovered on admin.google.com's ServiceNotAllowed page where the 'continue' parameter was not validated, allowing attackers to inject javascript: protocol URLs that execute when the page redirects, enabling account takeover and privilege escalation of Google Apps administrators.

admin.google.com Google Apps ziot
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details