Post

SSO Gadgets II: Unauthenticated Client-Side Template Injection to Account Takeover using SSO Gadget Chain

Post

SSO Gadgets: Escalate (Self-)XSS to ATO

Post

XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing