Back to directory
WRITEUP #3996

Story of a very lethal IDOR.

XSSIDORAccount takeover
by@_justYnot(Vedant Tekale)
Program
-
Published
Feb 17, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://vedanttekale20.medium.com/idor-that-allowed-me-to-takeover-any-users-account-129e55871d8
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS

Built with ❤️ by Shubham Rawat