XSS via file name - https://sms.indeed.com/signup/signage-details/

Disclosed by
CGuillaume
  • Program Indeed
  • Disclosed date almost 2 years ago
  • Reward $100
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by CGuillaume

XSS via file name - https://sms.indeed.com/signup/signage-details/

Activity