StudySmarter – XSS and Potential Account Takeover
How we discovered a Cross-Site Scripting vulnerability in the StudySmarter learning platform that allowed stealing authentication tokens and potentially taking over accounts.
Read more →Hello! My name is Philipp and I am an IT professional and DevOps Engineer from Germany. I work with modern cloud technologies and am a passionate advocate for free and open-source software – not just professionally, but also in my spare time. You can find my projects on GitHub and GitLab.
How we discovered a Cross-Site Scripting vulnerability in the StudySmarter learning platform that allowed stealing authentication tokens and potentially taking over accounts.
Read more →