google-cse

2 articles
sort: new top best
clear filter
0 5/10

Clickjacking vulnerability on Google Custom Search Engine (CSE) settings page allows attackers to trick users into deleting their CSE instances through UI redressing by overlaying fake buttons on an embedded iframe. Google rejected the finding as not severe enough despite the ability to delete user data.

Google CSE cse.google.com Akbar Kustirama
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 5/10

A stored XSS vulnerability was discovered in Google Custom Search Engine's promotion URL feature, where javascript: protocol handlers were not filtered, allowing attackers to inject malicious URLs that execute when victims click promoted results.

Google Custom Search Engine cse.google.com Sreeram
thesecurityexperts.wordpress.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details