airbnb

2 articles
sort: new top best
clear filter
0 8/10

Security researchers discovered an SSRF vulnerability on Airbnb's chat endpoint by chaining a third-party open redirect in LivePerson's API with path traversal via encoded backslashes, enabling arbitrary requests from the Airbnb server. The attack exploited LivePerson's visitorWantsToChat redirect parameter and path parameter traversal to bypass intended API boundaries.

Airbnb LivePerson Ben Sadeghipour Brett Buerhaus
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 8/10

A detailed technical writeup on chaining eight XSS vulnerabilities at Airbnb by sequentially bypassing JSON encoding, XSS filters, WAF protection using null-byte injection, CSP rules, and Chrome's XSS auditor through the listing_frame embeddable endpoint. The exploitation leverages semicolon injection, null-byte WAF evasion, JSON encoder quirks, and CSP weaknesses.

Airbnb Ben Sadeghipour Brett Buerhaus HackerOne Chrome XSS Auditor
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details