Content Injection On hire.withgoogle.com
Content Spoofing or Text Injection On hire.withgoogle.com
Text Injection |
I found some text injection on google web service
Steps to reproduce:
- 1. Visit the url and see the text attacker injection
- 2. https://hire.withgoogle.com/sign-in?error=noOauthAccount&emailAddress=please%20login%20on%20evil.com%20because%20someone%20try%20to%20login%20on%20your%20account%20and%20make%20your%20account
Sadly, google won't fix this bug. maybe because it's low risk.
Reference :
- https://hackerone.com/reports111094
- https://www.google.com/search?q=text+injection+hackerone&oq=text+injection+hackerone&aqs=chrome..69i57.6159j0j7&sourceid=chrome&ie=UTF-8
Google Respond |
Comments
Post a Comment