Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode |
|
|
|
POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows |
|
|
|
SSO Gadgets II: Unauthenticated Client-Side Template Injection to Account Takeover using SSO Gadget Chain |
|
|
|
SSO Gadgets: Escalate (Self-)XSS to ATO |
|
|
|
Personal Access Token Disclosure in Asana Desktop Application |
|
|
|
Flickr Account Takeover |
|
|
|
Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri |
|
|
|
XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing |
|
|
|
TikTok Careers Portal Account Takeover |
|
|
|
CVE-2020-13294 |
|
|
|