onedrive-integration

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a chain vulnerability in a third-party OneDrive integration by exploiting loose redirect_uri path validation in OAuth flow combined with a CSRF-enabling testCallback API endpoint, allowing theft of authorization codes and access tokens without user consent.

OneDrive Microsoft Live Login HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details