broken-access-control

2 articles
sort: new top best
clear filter
0 6/10

A critical IDOR vulnerability discovered through accidental observation of different URL parameter flows in a change-password endpoint, allowing unauthorized access to other users' accounts and subsequent email modification for account takeover.

Harsh Bothra OWASP TOP 10 targetsub.com
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details
0 7/10

A site-wide CSRF vulnerability was discovered on a popular program where the backend accepted form-encoded payloads (application/x-www-form-urlencoded) despite expecting JSON, because the server failed to strictly validate the Content-Type header. The attacker bypassed the false assumption that JSON-only handling would prevent CSRF by sending traditional form-based CSRF payloads.

Ajinkya Pathare
fellchase.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details