My First High-Severity Bug: Chaining Open Redirect and DOM XSS into Account Takeover
This was my first ever valid bug bounty report through a VDP, and it got marked High severity. It was also not a duplicate, so for me this was a huge win.
One thing I had heard a lot in bug bounty is
blog.ovawatch.co.za2 min read