WRITEUP #5267
OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect
Auth BypassOpen redirectToken leakAccount takeover
by@h1_sp1d3r(Evgeniy Yakovchuk)
Program
Airbnb
Published
Jul 10, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://xp.ht/oauth-authentication-bypass-on-airbnb-acquisition-using-weird-1-char-open-redirect/