Skip to main content

Posts

Featured

How I Escalated a RXSS to PII Leak + ATO on a SaaS Platform

On a very good day, I was scrolling through external BBPs because I was getting tired of grinding the same platform programs on Yeswehack and similar sites. I came across this SaaS company's bug bounty program, they're based in India, and the scope was massive with tons of products and huge attack surface.  My first report was a simple open redirect; They closed it as N/A, which was whatever - it was my first submission on their program anyway. The next day I went back to the target for more recon.  While enumerating subdomains, I hit app.[redacted].com , and that led me straight to a reflected XSS on their Marketplace product. The vulnerable URL looked like this - https://marketplace.[redacted].com/app/embed/billing/telegram-for-zoho-billing?mode=true&serviceOrg=920557526%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E&frameorigin=https://test.com It's a reflected Cross-Site Scripting (XSS) in the serviceOrg parameter. The app wasn't sanitizing the input ...

Latest Posts

URL Redirect Bypass via Weak String Validation Leading to Attacker-Controlled Domain Redirection

Breaking Directus CMS < 11.9.3 ( From Information Disclosure to Arbitrary File Overwrite )

How I Exploited a CORS Misconfiguration To a Full Account Takeover Chain