full-duplex-communication

1 article
sort: new top best
clear filter
0 7/10

Demonstrates how missing Origin header validation on WebSocket endpoints can allow cross-origin XSS and CSRF attacks. The attacker connects to an unprotected WebSocket, sends malicious payloads containing script tags that get rendered in the receiving client's DOM, achieving application-wide XSS and account takeover capabilities.

Osama Avvan BurpSuite websocket.org
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 13 hours ago · details