account-hijacking

2 articles
sort: new top best
clear filter
0 7/10

A clickjacking vulnerability in Instagram's account management endpoint allowed attackers to iframe AJAX responses containing connected application tokens and steal user credentials. The vulnerability existed because the `__a=1` parameter exposed sensitive token data in JSON format without X-Frame-Options protection, despite the regular UI having protections in place.

Instagram Facebook Mohamed A. Baset Mostafa Kassem Seekurity
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 3/10

Blog post describing two vulnerabilities found in Protonmail: a brute-force attack against a 10-digit password reset code for account hijacking, and a stored XSS vulnerability in the email inbox exploitable via malicious email subject lines. Both issues were reportedly patched by Protonmail.

Protonmail Chand Singh
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details