http-headers

1 article
sort: new top best
clear filter
0 7/10

A CORS misconfiguration vulnerability where a website trusts all origins ending with a specific domain (e.g., evilredacted.com for redacted.com), allowing an attacker who registers a predomain wildcard subdomain to make authenticated requests and steal session credentials via JavaScript. The attacker registers a domain like kiraakredacted.com and crafts a malicious page that calls the /v1/user API endpoint with credentials enabled to extract user session IDs.

Arbaz Hussain HackerOne PortSwigger InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details