client-side-vulnerability

4 articles
sort: new top best
clear filter
0 5/10

WhatsApp's web client was vulnerable to clickjacking attacks due to missing X-Frame-Options header and iframe busting techniques, allowing attackers to trick users into sending messages, creating groups, or making calls on their behalf. The vulnerability was reported to Facebook in January 2015 and subsequently fixed with an X-Frame-Options: Deny header.

WhatsApp Facebook Telegram Mohamed A. Baset Seekurity Brian Acton Jan Koum
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A DOM-based XSS vulnerability was discovered in Branch.io's attribution platform affecting 685+ million users across Tinder, Shopify, Yelp, and other major companies. The flaw exploited unvalidated GET parameters (redirect_strategy and scheme_redirect) to inject malicious payloads, with validation bypasses via indexOf() string matching and javascript:// protocol obfuscation.

Tinder Shopify Yelp Branch.io Western Union Imgur RobinHood Canva Letgo Cuvva Lookout fair.com vpnMentor Kristina Perunicic
vpnmentor.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10

Security researcher discovered a reflective XSS vulnerability and open redirect flaw on Indeed's offers.indeed.com subdomain via the 'target' URL parameter in a PDF report functionality. The vulnerability allowed arbitrary JavaScript execution and redirection to external sites, which was patched by Indeed within a week.

Indeed.com offers.indeed.com Sublist3r Bugcrowd Syntax Error
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10
vulnerability

Facebook's badges page was vulnerable to stored XSS via an unencoded 'layout' POST parameter that was directly saved to the database and rendered in HTML class attributes, allowing attackers to inject arbitrary HTML/JavaScript and perform actions on behalf of victims.

Facebook Mark Zuckerberg
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details