writeups.xyz writeups.xyz / Lauritz Holtmann (@_Lauritz_)

Title Vulnerabilities Programs Authors
Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode
POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows
SSO Gadgets II: Unauthenticated Client-Side Template Injection to Account Takeover using SSO Gadget Chain
SSO Gadgets: Escalate (Self-)XSS to ATO
Personal Access Token Disclosure in Asana Desktop Application
Flickr Account Takeover
Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri
XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing
TikTok Careers Portal Account Takeover
CVE-2020-13294