put-request

2 articles
sort: new top best
clear filter
0 7/10
vulnerability

A researcher chained CORS misconfiguration, XSS on a subdomain, and cookie scope issues to perform CSRF attacks and modify user account information. By exploiting a subdomain-scoped cookie and XSS on help.redact.com, they extracted an encryptedMembershipNumber cookie and sent unauthorized PUT requests to change user data.

Osama Avvan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

A reflected/stored XSS vulnerability in Ghost CMS's /ghost/api/v0.1/settings/ API endpoint affecting logo, cover_image, ghost_head, and ghost_foot parameters. While requiring authenticated admin/owner access, the vulnerability persists across multiple versions (1.24.9 through at least 2.2.0) and executes payloads on every page of the website.

Ghost VoidSec CORS Anywhere CVE (referenced but not specified)
itsecguy.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details