DOM XSS

AppWizard
June 27, 2024
The vulnerability in KakaoTalk allows attackers to leak user access tokens via the Authorization header, which can be used to take over the victim's Kakao mail account. Additionally, attackers can create new Kakao Mail accounts and access chat messages, with the ability to overwrite the user's previously registered mail address.
Search