Authentication bypass via OAuth implicit flow
This is a writeup for a challenge from PortSwigger's Web Security Academy. In this one, we will learn how a misconfigured OAuth authentication can be bypassed.
Objective
This lab uses an OAuth service to allow users to log in with their social media...
hacking4ra.men2 min read