cross-origin-request-forgery

1 article
sort: new top best
clear filter
0 6/10

A misconfigured CORS policy on a Bitcoin site's third-party contact form API allowed arbitrary origins with credentials enabled, enabling attackers to extract sensitive user data (name, email, phone, account ID) via a malicious webpage using XMLHttpRequest.

Arbaz Hussain HackerOne api.thirdparty.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details