writeups.xyz writeups.xyz / Osama Avvan (@Osamaavvan)

Title Vulnerabilities Programs Authors
Unauthenticated GraphQL Introspection and API calls
Exploiting WebSocket [Application Wide XSS / CSRF]
Exploiting JSONP and Bypassing Referer Check
CORS To CSRF Attack
$1800 worth Clickjacking
Account Takeover with Clickjacking
Bypassing XSS filter and Stealing User Payment Data
Stealing Cookies to Login in any Account