iframe-exploitation

1 article
sort: new top best
clear filter
0 5/10

Researcher discovered a CSRF vulnerability in a user deletion module lacking CSRF tokens, combined with numeric user ID brute-forcing to delete all application users. The attack bypassed X-Frame-Options and origin validation by using iframe-targeted requests.

Armaan Pathan HackerOne Bugcrowd OWASP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details