writeups.xyz writeups.xyz / Authorization Bypass

Title Vulnerabilities Programs Authors
Authorization bypass due to cache misconfiguration
The Hunt for ALBeast: A Technical Walkthrough
Bypassing Account Suspension Using Anonymous Posting | Facebook Bug Bounty
Hacking Millions of Modems (and Investigating Who Hacked My Modem)
Disclose Instagram Personal Private Archived posts when switching to Professional account through creative hub
Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform
Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3
GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts
Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server
Improper Privilege Management in Grails Spring Security Core <= 5.1.0 (CVE-2022-41923)
Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover
GitHub Security Lab audited DataHub: Here’s what they found
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
From a 500 error to Django admin takeover
Exploiting Admin Panel Like a Boss
We Hacked Apple for 3 Months: Here’s What We Found
Bypassing GitHub's OAuth flow