origin-misconfiguration

1 article
sort: new top best
clear filter
0 3/10

Researcher found a chain of vulnerabilities in Legal Robot: HTML injection leading to open redirect via META refresh tags, combined with a misconfigured WebSocket Origin header allowing CSRF attacks from different origins. The vulnerability chain required no XSS execution due to CSP but achieved account logout and malicious script execution through forced redirects.

Legal Robot HackerOne Armaan Pathan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details