Skip to content
April 21, 2026
☍ CyberNoz
  • Home
Home›Mix›CSRF protection on OIDC login is broken
Mix

CSRF protection on OIDC login is broken

Cybernoz
April 8, 2023 1 min read
Share X / Twitter LinkedIn Reddit WhatsApp Email



Nextcloud disclosed a bug submitted by mikaelgundersen: https://hackerone.com/reports/1878381



Source link

Share X / Twitter LinkedIn Reddit WhatsApp Email
« Previous
Top 3 Most Dangerous Lines of Code
Next »
Unveiling the Wild World of Bug Bounties

Related Articles

All Mix →
tldr sec 170 Prototype Pollution Fuzzing SOC Metrics scaled Mix

[tl;dr sec] #170 – Prototype Pollution, Fuzzing, SOC Metrics

Table of Contents Focusing on the Right Stuff 📢 Drata’s Compliance Trends Report 2023 📜 In this newsletter… Web Security 📢 We Hack Purple –…

March 20, 2023 Cybernoz 9 min read
My Philosophy and Recommendations Around the LastPass Breaches Mix

My Philosophy and Recommendations Around the LastPass Breaches

Table of Contents My thoughts on the situation Ok, but what do I do in the meantime? Notes If you follow Information Security at all…

April 20, 2023 Cybernoz 6 min read
RSA 2023 Top Trends Beyond AI Tools and Products Mix

RSA 2023: Top Trends – Beyond AI, Tools, and Products

AI Requires More Confidence and Clarity AI was less of a marketing play on the show floor than I expected, perhaps because cybersecurity has already…

May 4, 2023 Cybernoz 3 min read
The real impact of an Open Redirect vulnerability Mix

The real impact of an Open Redirect vulnerability

Table of Contents Header based Javascript based Oauth SSRF XSS-Auditor bypass Referrer check bypass How Detectify can help Detectify is building web app security solutions…

May 1, 2023 Cybernoz 6 min read
It’s The Culture, Stupid | Daniel Miessler Mix

It’s The Culture, Stupid | Daniel Miessler

In another post about culture a friend commented that we must guard against the idea that there is only one way to live. I agree…

April 1, 2025 Cybernoz 3 min read
Visualizing Live Hacking Events Hackers Break Records at H1 702 scaled Mix

Visualizing Live Hacking Events: Hackers Break Records at H1-702

Visualizing Live Hacking Events: Hackers Break Records at H1-702 Source link

April 17, 2023 Cybernoz 1 min read

Latest Posts

  • Mythos can find the vulnerability. It can’t tell you what to do about it.
  • ESET Threat Report H2 2025
  • Why identity is the driving force behind digital transformation
  • Attacking MSSQL Servers | Huntress
  • NGate Android malware uses HandyPay NFC app to steal card data
  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
☍ CyberNoz

Cybersecurity News

  • Agbi
  • ArsTechnica
  • AttackDefense
  • Australiancybersecuritymagazine
  • Bankinfosecurity
  • Bleeping Computer
  • CISOOnline
  • CloudSecurity
  • ComputerWeekly
  • Crowdstrike
  • Cyber Security Ventures
  • CyberDefenseMagazine
  • CyberNews
  • Cyberscoop
  • CyberSecurity-Insiders
  • CyberSecurityDive
  • CyberSecurityNews
  • CyberWire
  • DarkReading
  • ExploitOne
  • GBHackers
  • Genel
  • HackerCombat
  • HackRead
  • HelpnetSecurity
  • IndustrialCyber
  • InfoSecurity
  • ITnews
  • ITSecurityGuru
  • Krebson
  • MalwareBytes
  • Mix
  • OTSecurity
  • PortSwigger
  • Rapid7
  • SCMP
  • securelist
  • Securityaffairs
  • SecurityWeek
  • techcrunch
  • TheCyberExpress
  • TheHackerNews
  • ThreatIntelligence-IncidentResponse
  • Tldrsec
  • Unit42
  • VendorResearch
  • welivesecurity
  • Wired
  • Zerosalarium
Archive
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
© 2026 Cybernoz. All rights reserved.