local-file-disclosure

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered an SSRF vulnerability leading to local file disclosure by bypassing URL validation filters. The application rejected file:/// payloads but accepted file:// with a single path component (file://s/etc/passwd), allowing arbitrary local file access through a simulated browser feature.

Tung Pun Hackerone requestb.in Chrome/60.0.3112.101
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details