top | item 46321172

(no title)

arcwhite | 2 months ago

It's actually pretty on-par for most bug bounties. They used the same exploit on a few programs and got $11k total which ain't bad return on time.

discuss

order

sans_souse|2 months ago

No I know it's on par I guess better rephrasing would be the par is still too low

arcwhite|2 months ago

Compared to what? What's your baseline for how much a user-interaction-required XSS vulnerability should be worth?