authorization-header

1 article
sort: new top best
clear filter
0 8/10

A reflected XSS vulnerability in a URL parameter was chained with multiple design flaws (tokens stored in localStorage, lack of token revocation across devices, authorization via headers instead of cookies) to achieve persistent account takeover by stealing and replaying Cognito refresh tokens. The attacker could silently exfiltrate authentication tokens while clearing localStorage to make the victim believe they were logged out.

Amazon Cognito Milind Purswani Yash Sodha Angular
hackademic.co.in · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details