parameter-reflection

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered a cookie-based XSS vulnerability that became exploitable by moving the vulnerable cookie parameter into URL GET parameters, allowing them to exfiltrate session cookies without needing to chain additional vulnerabilities like CRLF injection.

Utkarsh Agrawal Burp Suite PHPSESSID
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details