2 ms·
Yeah if I would be working there it would be easy, have filed a lot of vuln reports/PR'd in the past at the startups I worked at. But the employment contract wa
by vulnfinder 11y ago
Yeah if I would be working there it would be easy, have filed a lot of vuln reports/PR'd in the past at the startups I worked at. But the employment contract was signed months ago and I'm not starting until soon, so can't file a bug report/contact a developer/create a PR.
The PoC is literally a URL, you open it and it shows arbitrary content injected by me through a query parameter. No user interaction required, no fields to enter, no login. They just forgot to sanitize their output, which seems quite easy to detect and fix.
Thanks for your reply though.