Collected research
Yelp ATO via XSS + Cookie Bridge
Yelp disclosed on HackerOne: yelp.com and biz.yelp.com ATO via XSS...
Chains a self-XSS in Yelp's unverified-email prompt with Yelp's cross-domain cookie bridge: the attacker signs the victim into an attacker account on yelp.dk so the XSS runs, then sets oversized cookies so the victim's own bridge transfer fails without consuming its one-time token, letting the attacker read the retrieve URL and take over the victim's HttpOnly session.
Record
- Document
- Yelp disclosed on HackerOne: yelp.com and biz.yelp.com ATO via XSS...
- Researcher
- lil_endian
- Published by
- HackerOne
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of lil_endian, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .