After learning about Google's bug bounty program, I decided to look for vulnerabilities on their most sensitive services. Finding a vulnerability on admin.google.com was challenging; I managed to find a simple, but interesting form of Cross-Site Scripting.
admin.google.com Reflected Cross-Site Scripting (XSS)
Author:
Brett Buerhaus
