Back to directory
WRITEUP #6130

"F**k you Thomas" - ToyTalk bug bounty writeup

Auth BypassAuthentication bypassHTML injection
byJahmel Harris
Program
ToyTalk
Published
Jan 4, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://research.digitalinterruption.com/2018/01/04/toytalk-bug-bounty-writeup/
RELATED WRITEUPS
Breaking the Barrier: Admin Panel Takeover Worth $3500
Auth BypassAuthentication bypass
SAML Authentication Bypass Leading to Admin Panel Access
Auth BypassSAML
Breaking Down Barriers: Exploiting Authenticated IPC Clients
Auth BypassIPC client
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat