same-origin-bypass

1 article
sort: new top best
clear filter
0 8/10

A stored XSS vulnerability in webcomponents.org allowed attackers to inject malicious JavaScript via repository homepage URLs, enabling theft of GitHub OAuth authorization codes and account hijacking to star repositories on behalf of authenticated users.

webcomponents.org GitHub Thomas Orlita Polymer
websecblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details