Cross-site scripting (XSS)
Injected scripts that execute in another user's session, stored or reflected.
Security researchers make BlueMail safer for everyone. If you find a vulnerability in our apps or infrastructure, report it responsibly and we'll reward you based on its severity.
Injected scripts that execute in another user's session, stored or reflected.
Requests that perform sensitive actions on behalf of a user without their intent.
Any input path that reaches a query and lets you read or modify data you shouldn't.
Bypassing login, escalating privileges or accessing another account's data.
Executing code on BlueMail servers or inside the apps through crafted input.
If it puts user data or accounts at real risk, we want to hear about it. When in doubt, report it.
Severity is assessed with you during triage, based on impact and exploitability.