Invitation tokens leak to Google Analytics
Low
Vulnerability Details
Hi,
While testing i have noticed that , the hackerone invitation token gets exposed to google-anaytics.com
How?
Here look at the photo-
████████
We can see that the request payload is exposing the invitation token and its not filtered like this one-
███████
And this is what google does with their request payload-
███████
So that means h1 is giving away invitation tokens to third party apps and letting them store it.
If i missed something ask me before closing the report
And requesting you to check this report- #237201
That report is about exposing private programs with valid POC
Actions
View on HackerOneReport Stats
- Report ID: 237262
- State: Closed
- Substate: resolved
- Upvotes: 31