A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues chained together into a critical account takeover vulnerability.IntroductionWhile testing a self-hosted platform during a bug bounty engagement, my teammate Kazi Sabbir and I discovered a series of OAuth misconfigurations that could be chained...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3619829