writeups.xyz writeups.xyz / Amazon Cognito Misconfiguration

Title Vulnerabilities Programs Authors
How I was able to takeover any account (Zero-click ATO)
Privilege Escalations through Integrations
Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1
AWS Cognito pitfalls: Default settings attackers love (and you should know about)
Account Take Over Due To AWS Cognito Misconfiguration
Account Takeover Due to Cognito Misconfiguration Earns Me €xxxx
Hunting for Amazon Cognito Security misconfigurations
I Obtained ADMIN access via the Account Activation link [In 30 seconds]