jwt-theft

1 article
sort: new top best
clear filter
0 7/10

A researcher chained a stored XSS vulnerability in a mindmap feature with JWT token theft from localStorage and an unauthenticated email-change endpoint to achieve full account takeover. The critical challenge was properly escaping JSON payloads nested within JavaScript code inside an SVG onload handler, which was ultimately solved using eval() to convert single-quoted JSON to double-quoted JSON.

Jatin Nandwana HackerOne localStorage XMLHttpRequest JWT
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details