Back to directory
WRITEUP #1886

WebView XSS, account takeover

XSSWebview XSSAndroidAccount takeoverImproper Export of Android Application Components
byshafou
Bounty
2,500
Program
-
Published
Nov 26, 2022
Added to HackDex
Nov 30, 2022
Read Full Writeuphttps://shafouz.medium.com/webview-xss-account-takeover-349c1d69606e
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass

Built with ❤️ by Shubham Rawat