Files
CVEs-PoC/2018/CVE-2018-19335.md
T
2024-06-18 02:51:15 +02:00

922 B

CVE-2018-19335

Description

Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.

POC

Reference

Github

No PoCs found on GitHub currently.