Back to directory
WRITEUP #1030

Account Takeover: Unraveling IDOR + Stored XSS Flaws in an NFT Marketplace

IDORStored XSSAccount takeover
by@PratikY9967(Pratik Yadav)
Program
-
Published
Jun 26, 2023
Added to HackDex
Jun 27, 2023
Read Full Writeuphttps://medium.com/@pratiky054/account-takeover-unraveling-idor-stored-xss-flaws-in-an-nft-marketplace-158679660fa7
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Self-XSS to ATO via Site Features
XSSSelf-XSS
Zomatoooo! IDOR in Saved Payments
IDOR
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat