Web Hack List

Collected research

Yelp ATO via XSS + Cookie Bridge

Yelp disclosed on HackerOne: yelp.com and biz.yelp.com ATO via XSS...

Chains a self-XSS in Yelp's unverified-email prompt with Yelp's cross-domain cookie bridge: the attacker signs the victim into an attacker account on yelp.dk so the XSS runs, then sets oversized cookies so the victim's own bridge transfer fails without consuming its one-time token, letting the attacker read the retrieve URL and take over the victim's HttpOnly session.

Record

Document
Yelp disclosed on HackerOne: yelp.com and biz.yelp.com ATO via XSS...
Researcher
lil_endian
Published by
HackerOne
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of lil_endian, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .