Back to directory
WRITEUP #253

Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode

XSSOIDCAccount takeoverCSP bypassWAF bypass
by@_lauritz_(Lauritz Holtmann)
Program
Tools for Humanity (Worldcoin)
Published
Jun 19, 2024
Added to HackDex
Jul 8, 2024
Read Full Writeuphttps://security.lauritz-holtmann.de/advisories/tfh-form_post-xss-ato/
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass
Type confusion attacks in ProseMirror editors
XSSType confusion
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS

Built with ❤️ by Shubham Rawat