Content Spoofing OR Text Injection in https://gitlab.com
HackerOne report #504961 by mkzreport
on 2019-03-04, assigned to dappelt
:
Hello,
i want to report Content Spoofing OR Text-based injection vulnerability
the bug exists at :
https://gitlab.com/users/auth/github/callback?state=cae8687aa809fc45e00b2f8ed4a0ea124d5f9b8235cb2b2e&error_description=YOUR+ACCOUNT+WAS+LOCKED,PLEASE+GO+TO+https://evil.com+FOR+UNLOCKING+YOUR+ACCOUNT&error=access_denied
Impact
That means above mention URL's parameter is vulnerable for Content Spoofing OR Text Injection
Attachments
Warning: Attachments received through HackerOne, please exercise caution!