Parameter pollution in social sharing buttons
Unknown
Vulnerability Details
Hello! For example we have a link `https://hackerone.com/blog/introducing-signal-and-impact`, and we will change it to `https://hackerone.com/blog/introducing-signal-and-impact?&u=https://vk.com/durov`. If you send a link to the user and he wants to share a link to facebook, the content will change.
`https://www.facebook.com/sharer.php?u=https://hackerone.com/blog/introducing-signal-and-impact?&u=https://vk.com/durov`
Actions
View on HackerOneReport Stats
- Report ID: 105953
- State: Closed
- Substate: resolved
- Upvotes: 55