writeups.xyz writeups.xyz / Serj Novoselov (@Novoselov_s)

Title Vulnerabilities Programs Authors
Forced SSO Session Fixation
XML External Entity injection with error-based data exfiltration
XSS on the Oauth callback URL with CSP bypass leading to zero-click account takeover
https://infosecwriteups.com/exploiting-incorrectly-configured-load-balancer-with-xss-to-steal-cookies-99d7cb6129d7
Critical vulnerability on TP-Link service or how I got 0$