Image Injection on `/bully/anniversaryedition` may lead to FB's OAuth Token Theft.
Medium
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher identified a chain of attacks that could result in sensitive token leakage, such as Oauth tokens. The attack would begin with an image injection exploit on the page at `https://www.rockstargames.com/bully/anniversaryedition`. That exploit was the focus of this particular report, with other parts of the attack chain being addressed in separate reports. We put out an update to the site resolving the image injection vulnerability, thus preventing this attack.
Actions:
Reported by
netfuzzer
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure