|
|
|
|
|
by justsomeuser
2115 days ago
|
|
I found a XSS bug in a popular note taking app. It would allow an attacker to download all the users notes just by having them visit a URL. I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one. It was marked as "medium", I got $250 for it. |
|
https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...