admin-creation

1 article
sort: new top best
clear filter
0 7/10

A reflected XSS vulnerability in an OAuth2 redirect_uri parameter was escalated from simple alert injection to account takeover by extracting CSRF tokens from meta tags and automating admin user creation without authentication. The writeup demonstrates a practical methodology for showing XSS impact through functional exploitation rather than simple proof-of-concept.

HackerOne XMLHttpRequest FormData
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details