third-party-vulnerability

1 article
sort: new top best
clear filter
0 7/10

A DOM-based XSS vulnerability was discovered in Branch.io's attribution platform affecting 685+ million users across Tinder, Shopify, Yelp, and other major companies. The flaw exploited unvalidated GET parameters (redirect_strategy and scheme_redirect) to inject malicious payloads, with validation bypasses via indexOf() string matching and javascript:// protocol obfuscation.

Tinder Shopify Yelp Branch.io Western Union Imgur RobinHood Canva Letgo Cuvva Lookout fair.com vpnMentor Kristina Perunicic
vpnmentor.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details