csrf-token-theft

1 article
sort: new top best
clear filter
0 3/10

Researcher chained IDOR and stored XSS vulnerabilities to achieve account takeover on all users by injecting malicious JavaScript into a shared element, and separately discovered blind XSS in an invoice generation feature that exposed customer data in the admin panel. Both findings resulted in $3,500 bounties each.

Tabahi Bull Hackerone XSSHunter WitCoat Security
blog.witcoat.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details