internal-file-read

1 article
sort: new top best
clear filter
0 6/10

A bug bounty hunter discovered an SSRF vulnerability via a JavaScript file parameter that allowed reading internal files (like /etc/passwd) using the file:// URL scheme, leading to a successful disclosure and bounty.

Neeraj Sonaniya unminify.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details