With the rise of Single-Sign-On (SSO) and especially OAuth 2.0 and OpenID Connect (OIDC), the attack surface of web applications has increased significantly. In this post, I will show how to escalate a Cross-Site Scripting (XSS) vulnerability to an Account Takeover (ATO) by abusing OAuth2/OIDC gadgets and how to prevent such attacks.
Ähnliche Beiträge
Auch interessante Nachrichten SSO Gadgets: Escalate (Self-)XSS to ATO
Thematisch verwandte Begriffe: Gadgets, Escalate, SelfXSS · 6 Treffer
How I Turned Self-XSS into Reflected XSS (and Bypassed the WAF)
drakoarmy/datadome-rs: High-end Rust DataDome deobfuscator & solver with VM disassembly — all 3 challenge types (tags, interstitial, slider).
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients
[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)
[webapps] Bludit CMS - Stored XSS
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
SOCIAL SHARE CARD GENERATOR