token-leakage

1 article
sort: new top best
clear filter
0 2/10

A CORS misconfiguration on Kaggle's 404 page allowed cross-origin requests to leak CSRF tokens from the page source, which could be combined with CSRF vulnerabilities to generate API keys on behalf of users. The researcher received a Google VRP reward for this chained vulnerability.

Google Kaggle Jayateertha Guruprasad Google VRP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details