Back to directory
WRITEUP #3569

Mattermost Server v5.32 > v5.36 Reflected XSS in OAuth flow

XSSReflected XSSOAuth
by@zi0Black(zi0Black)
Bounty
900
Program
Mattermost
Published
Jul 26, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://www.shielder.it/advisories/mattermost-server-reflected-xss-oauth/
RELATED WRITEUPS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
Over 1 Million websites are at risk of sensitive information leakage - XSS is dead. Long live XSS
XSSOAuth
Self-XSS to ATO via Site Features
XSSSelf-XSS
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass

Built with ❤️ by Shubham Rawat