mobile-api

1 article
sort: new top best
clear filter
0 5/10

A CORS misconfiguration on a mobile app API was discovered that reflected user-controlled origin headers with Access-Control-Allow-Credentials enabled, allowing credential-based cross-origin requests. Though the vulnerability had high attack complexity (requiring manual cookie injection to exploit), it was confirmed through a proof-of-concept that successfully accessed sensitive account information from the attacker's domain.

Smaran Chand Bugcrowd Frida Burp Suite Firefox
smaranchand.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details