api-key-leakage

1 article
sort: new top best
clear filter
0 5/10

A bug bounty researcher demonstrates an account takeover vulnerability combining stored XSS, information disclosure (API key leakage via group chat endpoints), and JSON-based CSRF using XMLHttpRequest to escalate from low-privilege user to admin account takeover. The attack exploited lack of CSRF protection on API endpoints that relied solely on API key validation.

shub rathore sil3nt_4unt3r HackerOne Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 13 hours ago · details