uber.com may RCE by Flask Jinja2 Template Injection

Program: uber Bug Type: CSTI Bounty: Unspecified Date: 2017-05-20
CSTI stored-XSS

Summary

The researcher found a Client side template injection in the address saving feature of wordpress that lets a user put in template code and get it executed in addresses section. This was classified as a stored self xss as there is no way for another client to access the endpoint where the XSS is stored.

References