Invitation tokens leak to Google Analytics

Disclosed: 2017-07-16 16:41:58 By h33tjev To security
Low
Vulnerability Details
Hi, While testing i have noticed that , the hackerone invitation token gets exposed to google-anaytics.com How? Here look at the photo- ████████ We can see that the request payload is exposing the invitation token and its not filtered like this one- ███████ And this is what google does with their request payload- ███████ So that means h1 is giving away invitation tokens to third party apps and letting them store it. If i missed something ask me before closing the report And requesting you to check this report- #237201 That report is about exposing private programs with valid POC
Actions
View on HackerOne
Report Stats
  • Report ID: 237262
  • State: Closed
  • Substate: resolved
  • Upvotes: 31
Share this report