Unauthenticated GraphQL Introspection and API calls |
|
|
|
Exploiting WebSocket [Application Wide XSS / CSRF] |
|
|
|
Exploiting JSONP and Bypassing Referer Check |
|
|
|
CORS To CSRF Attack |
|
|
|
$1800 worth Clickjacking |
|
|
|
Account Takeover with Clickjacking |
|
|
|
Bypassing XSS filter and Stealing User Payment Data |
|
|
|
Stealing Cookies to Login in any Account |
|
|
|