web-cache-poisoning

1 article
Sort: New Top Best
clear filter
0 5/10

A researcher discovered a reflected XSS vulnerability in a language parameter that was cached by the web server, escalating it to account takeover by leveraging web cache poisoning to persist the malicious payload across all users visiting the site, exploiting missing HttpOnly/Secure cookie flags and lack of CSP.

lutfumertceylan.com.tr · kh4sh3i/bug-bounty-writeups · 4 hours ago · details