open-redirect

8 articles
Sort: New Top Best
clear filter
0

Researchers discovered an SSRF vulnerability on Airbnb by chaining a third-party open redirect in LivePerson's chat integration, leveraging automated JavaScript endpoint discovery and LivePerson's visitorWantsToChat API parameter to redirect internal API requests to attacker-controlled URLs. Additionally, relative path traversal via encoded backslashes in the path parameter enabled access to non-API endpoints on the LivePerson domain.

Airbnb LivePerson Ben Sadeghipour Brett Buerhaus
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xpoc.pro · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · Bugitrix · 8 hours ago · details
0 2/10

A clickbait Medium article claiming to demonstrate how to earn $500 from an open redirect vulnerability, but provides no actual technical details, methodology, or exploitation steps.

medium.com · Bugitrix · 8 hours ago · details
0
bugreader.com · Sarmad Hassan · 126 years ago · details
0
medium.com · Ashok Chapagai · 126 years ago · details
0
ysamm.com · Samm0uda · 126 years ago · details