browser-based-attack

1 article
sort: new top best
clear filter
0 6/10

A security researcher chained stored iframe injection with CSRF to achieve account takeover by injecting a malicious iframe into a discussion forum that, when loaded by an admin, silently executed a CSRF attack to change the victim's email address. The attack exploited HTML injection in the reply feature combined with an unprotected email change endpoint.

Rounak Dhadiwal Burp Collaborator PortSwigger AWS
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details