![]() |
|
HackerOne Disclosed Reports - 2026-06-01 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-06-01 (/Thread-HackerOne-Disclosed-Reports-2026-06-01) |
HackerOne disclosed reports - 2026-06-01 - hashXploiter - 06-02-2026
High
resolved page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token CompromiseBug reported by Natthakul Raingoen was disclosed at June 2, 2026, 3:30 am | An open redirect vulnerability was identified in page.line.me because redirect destinations were not properly restricted to trusted domains. This vulnerability could have been abused within an OAuth 2.0 authorization flow to cause the authorization response to be sent to an attacker-controlled endpoint, potentially exposing the authorization code issued after successful user authentication. |