secure-flag

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a Reflected XSS vulnerability in a video game company's language parameter that, when combined with weak web cache poisoning behavior, allowed cached payload execution across all site pages and enabled account takeover through session cookie theft (due to missing HttpOnly and Secure flags).

Lütfü Mert Ceylan OWASP Detectify PortSwigger Zerocopter
lutfumertceylan.com.tr · kh4sh3i/bug-bounty-writeups · 7 hours ago · details