session-token-theft

1 article
sort: new top best
clear filter
0 3/10

Demonstrates stealing authentication tokens stored in browser local storage via stored XSS on an admin account, using an img onerror payload to exfiltrate data to an attacker server. The researcher found this vulnerability on a Bugcrowd private program and was awarded $800.

bugcrowd OLX localStorage.getItem()
blog.h4rsh4d.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details