user-data-exposure

1 article
sort: new top best
clear filter
0 5/10

A CORS misconfiguration on api.artsy.net allowed attackers to exfiltrate sensitive user data (email, phone, authentication tokens, etc.) by crafting a malicious webpage that leverages the overly permissive Access-Control-Allow-Credentials and Access-Control-Allow-Origin headers to make cross-origin requests with victim credentials.

api.artsy.net Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details