domain-registration-bypass

1 article
sort: new top best
clear filter
0 7/10

A CORS misconfiguration vulnerability where the server's origin validation logic uses flawed regex/string matching that accepts malformed origin headers (e.g., 'private1com' instead of 'private.com'), allowing an attacker to register a lookalike domain and exfiltrate credentials and private information via a crafted CORS-enabled request.

Virus0X01 offensive hunterr
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details