skype

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered multiple stored and blind XSS vulnerabilities in Skype subdomains (manager.skype.com and secure.skype.com) via unsanitized group_name parameter that could be exploited to escalate privileges, execute malicious scripts on other users, and achieve account takeover through credential/cookie theft.

Jayateertha Guruprasad manager.skype.com secure.skype.com Microsoft XSSHunter CVE not provided
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details