Terminal

// Tag01 entries

Vuln & CVE

Everything filed under Vuln & CVE, newest first.

Write-ups

[TARGET]
HackerOne
[SEVERITY]
critical
[CLASS]
Vuln & CVE

An IDOR that became account takeover through OAuth

The object reference was only half of it. This follows the OAuth binding that trusted a client-supplied identifier, and the full takeover it allowed.

[TOOLS]burppython

1 min