data-disclosure

1 article
sort: new top best
clear filter
0 6/10

A security researcher exploited missing X-FRAME-OPTIONS headers on API endpoints that exposed sensitive user data (credit card, email, address) by creating a clickjacking attack that tricked users into copying and pasting API responses via an invisible iframe, earning $1800 in bug bounty rewards.

Osama Avvan Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details