oauth-misconfiguration

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered a reflected XSS vulnerability in Zomato's OAuth2 authentication endpoint by enumerating subdomains, finding that user input was reflected without proper sanitization. The XSS was bypassed using a marquee tag with onfinish handler and unicode-encoded confirm() function to evade WAF filters.

Zomato Sudhanshu Rajbhar secretx.zomato.com auth2.zomato.com Hydra Somdev Prateek Tiwari CVE (HackerOne #456333)
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details