writeups.xyz writeups.xyz / Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation

Submitter : c2a

Date: 29 January 2023

Bounty : 62,500

Vulnerabilities :

Programs :

Authors :

Link :
https://ysamm.com/?p=783