logoalt Hacker News

tptaceklast Thursday at 10:20 PM3 repliesview on HN

No it would not have been.


Replies

notnullorvoidyesterday at 1:06 AM

This specific XSS vulnerability may not have been, but the linked RCE vulnerability found by their friend https://kibty.town/blog/mintlify/ certainly would've been worth more than the $5,000 they were awarded.

A vulnerability like that (or even a slightly worse XSS that allowed serving js instead of only svg) could've let them register service workers to all visiting users giving future XSS ability at any time, even after the original RCE and XSS were patched.

show 1 reply
tuhgdetzhhlast Thursday at 10:43 PM

Could you elaborate on why not?

show 2 replies
Liongalast Thursday at 10:43 PM

It would have been. Ten times the amount at least.

show 2 replies