Possibility to inject a malicious JavaScript code in any file on tags.tiqcdn.com results in a stored XSS on any page in most Uber domains

Disclosed: 2018-11-13 22:54:03 By mdv To uber
High
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 256152
  • State: Closed
  • Substate: resolved
  • Upvotes: 49
Share this report