state-parameter-bypass

1 article
sort: new top best
clear filter
0 7/10

A researcher chained an AngularJS template injection self-XSS vulnerability with a misconfigured OAuth implementation that failed to validate the presence of the state parameter, allowing them to connect an attacker's Dropbox account to victim accounts and import malicious files containing XSS payloads, resulting in stored XSS execution.

Rohan Aggarwal HackerOne Dropbox Google Drive
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details