bug-bounty480
google298
xss277
microsoft249
facebook212
rce160
apple150
exploit137
bragging-post102
account-takeover98
malware94
csrf84
cve80
privilege-escalation74
stored-xss65
authentication-bypass64
writeup61
reflected-xss57
react54
browser54
ssrf51
cloudflare51
dos50
phishing50
access-control49
input-validation48
cross-site-scripting48
node47
docker46
aws46
sql-injection45
smart-contract45
ethereum44
web-security43
defi43
supply-chain43
web-application42
oauth41
web339
burp-suite36
lfi35
idor34
vulnerability-disclosure34
html-injection33
race-condition32
smart-contract-vulnerability32
reverse-engineering31
clickjacking31
information-disclosure30
csp-bypass30
0
7/10
A researcher chained an AngularJS template injection self-XSS vulnerability with a misconfigured OAuth implementation that failed to validate the presence of the state parameter, allowing them to connect an attacker's Dropbox account to victim accounts and import malicious files containing XSS payloads, resulting in stored XSS execution.
oauth
stored-xss
angularjs-template-injection
self-xss
state-parameter-bypass
file-upload
third-party-integration
chain-vulnerability
Rohan Aggarwal
HackerOne
Dropbox
Google Drive