CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload. |
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. |