javascript-analysis

2 articles
sort: new top best
clear filter
0 8/10

Security researchers discovered an SSRF vulnerability on Airbnb's chat endpoint by chaining a third-party open redirect in LivePerson's API with path traversal via encoded backslashes, enabling arbitrary requests from the Airbnb server. The attack exploited LivePerson's visitorWantsToChat redirect parameter and path parameter traversal to bypass intended API boundaries.

Airbnb LivePerson Ben Sadeghipour Brett Buerhaus
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

A bug bounty hunter discovered an SSRF vulnerability via a JavaScript file parameter that allowed reading internal files (like /etc/passwd) using the file:// URL scheme, leading to a successful disclosure and bounty.

Neeraj Sonaniya unminify.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details