Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2945Chaining CORS by Reflected xss to Account takeover #My first Blog CORS misconfiguration Reflected XSS Account takeover NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2020-12-262023-06-13
2842Stealing Chat session ID with CORS and execute CSRF attack CSRF CORS misconfiguration NA Sunil Yedla (@sunilyedla2) Bug Bounty2021-02-022023-06-13
2748Exploiting CORS to perform an IDOR Attack leading to PII Information Disclosure CORS misconfiguration Information disclosure NA Harsh Parekh (@notmarshmllow) Bug Bounty2021-03-012023-06-13
2531CORS misconfig that worths USD200 CORS misconfiguration NA MikeChan Bug Bounty2021-05-232023-06-13
1928Cross-Origin Resource Sharing (CORS) Misconfiguration leads to User’s PII leaks. CORS misconfiguration NA Tarikul Islam (@sa1tama0) Bug Bounty2022-01-102023-06-13
1104Fun With CORS CORS misconfiguration Token leak NA Talis Ozols Bug Bounty2022-09-082023-06-13
1021The forgotten IPFS vulnerabilities Web3 hacking Path traversal CORS misconfiguration HTML injection Filecoin Security tintinweb Bug Bounty2022-09-282023-06-13
854Compromising Plesk Via Its REST API CORS misconfiguration CSRF Plesk Adrian Tiron (@Adrian__T) Bug Bounty2022-11-082023-06-13
774Exploiting CORS Misconfigurations CORS misconfiguration CSRF XST Apple Google Mozilla (Firefox) WHATWG scarlet / attack ships on fire Bug Bounty2022-11-262023-06-13
718CORS Misconfig on Out of scope domain Bug Bounty Writeup (300 USD Reward ) CORS misconfiguration NA Eagle_92 Bug Bounty2022-12-082023-06-13
684Simple CORS misconfig leads to disclose the sensitive token worth of $$$ CORS misconfiguration Token leak Linear Ramalingasamy Bug Bounty2022-12-162023-06-13
625Bypass firewalls with of-CORs and typo-squatting CORS misconfiguration Tesla Chris Grayson Bug Bounty2023-01-022023-06-13
623Vue JS Reflected XSS Reflected XSS Blind XSS CORS misconfiguration UI redressing NA sid0krypt (@Siddhar07949650) Bug Bounty2023-01-032023-06-13
614Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability CORS misconfiguration Google Borna Nematzadeh (@LogicalHunter) Bug Bounty2023-01-062023-06-13
569EmojiDeploy: Smile! Your Azure web service just got RCE’d ._. RCE Cloud CSRF CORS misconfiguration Microsoft (Azure) Liv Matan (@terminatorLM) Bug Bounty2023-01-192023-06-13
553How i Hacked Scopely with “Sign in with Google” Account takeover CORS misconfiguration Client-side enforcement of server-side security OAuth Scopely Ph.Hitachi Bug Bounty2023-01-232023-06-13
455Bypassing CORS configurations to produce an Account Takeover for Fun and Profit CORS misconfiguration Account takeover NA Josh Fam (@Pullerze) Bug Bounty2023-02-132023-06-13
122A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF… postMessage JSONP DOM XSS CORS misconfiguration CSRF WAF bypass NA Julien Cretel (@jub0bs) Bug Bounty2023-05-052023-06-13