|
|
|
|
|
by mpeg
175 days ago
|
|
Yes, but this is not a particularly high access level bug. Depending on the target, it's possible that the most damage you could do with this bug is a phishing attack where the user is presented a fake sign-in form (on a sketchy url) I think $4k is a fair amount, I've done hackerone bounties too and we got less than that years ago for a twitter reflected xss |
|
In addition this is widespread. It's golden for any attacker.