redirect-uri

1 article
sort: new top best
clear filter
0 7/10

A CSRF vulnerability in Facebook's OAuth Device Login flow allowed attackers to steal user access tokens by exploiting the lack of state parameter protection during the device code verification step. The attack required the victim to have approved an application with device login enabled, making it a conditional but potentially high-impact vulnerability.

Facebook Josip Franjković graph.facebook.com m.facebook.com
josipfranjkovic.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details