bug-bounty480
google298
xss277
microsoft249
facebook212
rce160
apple150
exploit137
bragging-post102
account-takeover98
malware94
csrf84
cve80
privilege-escalation74
stored-xss65
authentication-bypass64
writeup61
reflected-xss57
react54
browser54
cloudflare51
ssrf51
dos50
phishing50
access-control49
cross-site-scripting48
input-validation48
node47
docker46
aws46
smart-contract45
sql-injection45
ethereum44
defi43
supply-chain43
web-security43
web-application42
oauth41
web339
burp-suite36
lfi35
idor34
vulnerability-disclosure34
html-injection33
race-condition32
smart-contract-vulnerability32
reverse-engineering31
clickjacking31
csp-bypass30
information-disclosure30
0
4/10
bug-bounty
A self-XSS vulnerability discovered on Indeed.com's job alert creation feature where injected JavaScript (via img onerror handler) could execute in the user's browser and steal cookies. The author documents their first bug bounty experience, including lessons learned about proper vulnerability reporting and escalation.
xss
self-xss
bug-bounty
web-vulnerability
indeed.com
html-injection
javascript-injection
cookie-theft
first-bug-bounty
Indeed.com
Sampanna Chimoriya
Google.com