404-page

1 article
sort: new top best
clear filter
0 2/10

A CORS misconfiguration on Kaggle's 404 page allowed cross-origin requests to leak CSRF tokens from the page source, which could be combined with CSRF vulnerabilities to generate API keys on behalf of users. The researcher received a Google VRP reward for this chained vulnerability.

Google Kaggle Jayateertha Guruprasad Google VRP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details