withgoogle

1 article
sort: new top best
clear filter
0 6/10

Writeup of three bugs submitted to Google VRP: a reflected XSS in artsexperiments.withgoogle.com discovered via ParamSpider and kxss automation, and two IDORs in AppSheet endpoints where access control could be bypassed—one requiring a specific version parameter to exploit. The author details the discovery process, initial rejections, and eventual acceptance with $500 bounties awarded.

Google VRP AppSheet ParamSpider kxss artsexperiments.withgoogle.com appsheet.com Sudhanshu Rajbhar
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details