origin-header

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A researcher chained CORS misconfiguration, XSS on a subdomain, and cookie scope issues to perform CSRF attacks and modify user account information. By exploiting a subdomain-scoped cookie and XSS on help.redact.com, they extracted an encryptedMembershipNumber cookie and sent unauthorized PUT requests to change user data.

Osama Avvan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details