![]() |
|
HackerOne Disclosed Reports - 2026-10-02 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-10-02 (/Thread-HackerOne-Disclosed-Reports-2026-10-02) |
HackerOne disclosed reports - 2026-10-02 - hashXploiter - 10-03-2026
High
resolved One-click cross-account JavaScript execution steals a victim write token through Turbo pagination and unattached Active Storage HTMLBug reported by Pirikara was disclosed at October 2, 2026, 5:19 pm | Cross-site Scripting (XSS) - Reflected A cross-account JavaScript execution vulnerability was discovered in a web application that allowed arbitrary code execution when a victim opened a crafted public board URL. An attacker with a separate account could leverage this vulnerability to steal the victim's write access token through a combination of flaws involving pagination parameter handling, unattached Active Storage HTML files, and inadequate MIME type validation. The stolen token was used to create, read, and delete data across the victim's accounts without authorization. The vulnerability required victim interaction through opening a single URL and affected confidentiality and integrity of victim data across unrelated accounts. |