indeed.com

1 article
sort: new top best
clear filter
0 4/10

A self-XSS vulnerability discovered on Indeed.com's job alert creation feature where injected JavaScript (via img onerror handler) could execute in the user's browser and steal cookies. The author documents their first bug bounty experience, including lessons learned about proper vulnerability reporting and escalation.

Indeed.com Sampanna Chimoriya Google.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details