UN United Nations Host Header Injection leads to any Full Account Takeover (ATO) |
|
|
|
stored XSS and stored HTML Injection in United Nations Website |
|
|
|
IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles |
|
|
|
XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain |
|
|
|