OAuth Misconfiguration Leading to Unauthorized Admin Access For All Org Products
TL;DR ?
I signed up using any unclaimed email on application_2 (e.g., victim@example.com) due to no email verification, then logged into the victim's account on application_1 using the SSO feature that allowed me to log in using application_2.
Introd...
hackt.us3 min read
Md Taqui imam
๐ Full Stack Web Developer & Programmer ๐
Thank you for a great explanation !