Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
3059
CVE-2020-13294
Authentication flaw
OpenID Connect
OAuth
GitLab
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2020-11-01
2023-06-13
2965
TikTok Careers Portal Account Takeover
CSRF
Open redirect
Account takeover
TikTok
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2020-12-15
2023-06-13
2672
XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing
XSS
HTML injection
NA
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2021-04-02
2023-06-13
2098
Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri
OAuth
Prototype pollution
GitHub
Microsoft
StackExchange
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2021-11-06
2023-06-13
1990
Flickr Account Takeover
Account takeover
Authentication flaw
Flickr
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2021-12-18
2023-06-13
1449
Personal Access Token Disclosure in Asana Desktop Application
Information disclosure
Hardcoded credentials
Asana
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2022-06-18
2023-06-13
497
SSO Gadgets: Escalate (Self-)XSS to ATO
SSO
OAuth
Account takeover
Self-XSS
Login CSRF
NA
Lauritz Holtmann (@_lauritz_)
Bug Bounty
2023-02-04
2023-06-13