Skip to content
June 1, 2026
☍ CyberNoz
  • Home
Home›Mix›CSRF protection on OIDC login is broken
Mix

CSRF protection on OIDC login is broken

Cybernoz
April 8, 2023 1 min read
Share X / Twitter LinkedIn Reddit WhatsApp Email



Nextcloud disclosed a bug submitted by mikaelgundersen: https://hackerone.com/reports/1878381



Source link

Share X / Twitter LinkedIn Reddit WhatsApp Email
« Previous
Top 3 Most Dangerous Lines of Code
Next »
Unveiling the Wild World of Bug Bounties

Related Articles

All Mix →
Reverse Engineering Granola to Get Notes In Obsidian · Joseph Thacker Mix

Reverse Engineering Granola to Get Notes In Obsidian · Joseph Thacker

I love granola.ai. Everyone I know is using it for meeting transcription. I’ve been using it to transcribe my calls and meetings for months. But…

May 8, 2025 Cybernoz 6 min read
What Is a Securitytxt File and How Can It Help Mix

What Is a Security.txt File and How Can It Help Your Program?

Table of Contents How Security.txt Helps Your Program How To Setup a Security.txt File Don’t Have a Vulnerability Disclosure Program or Bug Bounty?  Start a…

April 23, 2023 Cybernoz 5 min read

Hive Five 216 – The Hacker Always Wins

Table of Contents The Bee's Knees Hive Five Premium membership Table of Contents Updates Work Level up Explore Learned something? Habits are so good. They…

March 27, 2025 Cybernoz 9 min read
Why You Shouldn’t Be Calling Yourself Agnostic Mix

Why You Shouldn’t Be Calling Yourself Agnostic

Table of Contents Agnosticism Atheism Conclusion September 4, 2009 — After much spirited debate I have come to the conclusion that the argument presented below…

April 12, 2025 Cybernoz 5 min read

Increase developer confidence with a great Django test suite

How to write tests for your Django applications that are painless and productive. Done correctly, tests are one of your application’s most valuable assets. The…

April 14, 2023 Cybernoz 5 min read
Hacker monkeys  rez0 Mix

Hacker monkeys · rez0

A collection of AI-generated Hacker Monkeys If you want to see an image in full resolution, you can right click on the image and select…

April 6, 2023 Cybernoz 1 min read

Latest Posts

  • CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)
  • Flowise’s MCP implementation can run ghost commands
  • Dragos acquires Phosphorus to expand cybersecurity protection across the xOT environment
  • Xage integrates with NVIDIA DOCA security to deliver visibility, governance, and control across agentic AI environments
  • Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user account
  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
☍ CyberNoz

Cybersecurity News

  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
Archive
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
© 2026 Cybernoz. All rights reserved.