<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>LogicalBreach Academy Feed</title>
        <link>https://academy.logicalbreach.com/</link>
        <description>Latest bug bounty writeups, tools and security cheatsheets</description>
        <language>en-us</language>
        <lastBuildDate>Thu, 30 Jul 2026 04:54:41 GMT</lastBuildDate>
        <atom:link href="https://academy.logicalbreach.com//api/rss" rel="self" type="application/rss+xml" />
        
        <item>
            <title><![CDATA[Wildcard Account Lookup and Unsalted Hash Identifiers Defeat PII Masking]]></title>
            <link>https://academy.logicalbreach.com//writeups/wildcard-account-lookup-and-unsalted-hash-identifiers-defeat-pii-masking-202f1403</link>
            <guid isPermaLink="false">26159660-6cf5-4c06-b43a-4b63c94fb280</guid>
            <pubDate>Tue, 21 Jul 2026 18:54:37 GMT</pubDate>
            <description><![CDATA[An account-recovery API interpreted the supplied email selector as a wildcard pattern, allowing unauthenticated enumeration of arbitrary users. Although email addresses and phone numbers were visually masked, the API returned unsalted SHA-256 identifiers derived directly from the original values, making the masked PII recoverable. The report was accepted as High with CVSS 7.5 and rewarded with €400.]]></description>
        </item>
        <item>
            <title><![CDATA[Pre-Authentication Payroll History IDOR via a Client-Supplied Employee Identifier]]></title>
            <link>https://academy.logicalbreach.com//writeups/pre-authentication-payroll-history-idor-via-a-client-supplied-employee-identifier-20659bac</link>
            <guid isPermaLink="false">c4269ee2-9e3e-45ca-aa95-9ecb0683bce5</guid>
            <pubDate>Tue, 21 Jul 2026 18:52:14 GMT</pubDate>
            <description><![CDATA[A server-side object authorization flaw in a payroll API allowed an attacker to keep their own identity fixed while changing only the employee identifier in the request path. This exposed other employees’ complete payment histories, including payment amounts, debt adjustments, payroll periods and internal observations.]]></description>
        </item>
        <item>
            <title><![CDATA[Unauthenticated Oracle Boolean-Based SQL Injection Through a Legacy Search Filter]]></title>
            <link>https://academy.logicalbreach.com//writeups/unauthenticated-oracle-boolean-based-sql-injection-through-a-legacy-search-filter-4f97867e</link>
            <guid isPermaLink="false">87b3befd-797a-431b-a737-7a8e662190fb</guid>
            <pubDate>Tue, 21 Jul 2026 18:46:49 GMT</pubDate>
            <description><![CDATA[An unauthenticated boolean-based SQL injection was identified in a legacy Oracle-backed web application. A non-correlated scalar subquery was used to turn an Oracle error into a reliable boolean oracle, enabling character-by-character extraction of database metadata and any data accessible to the application account. The report was accepted as Critical with CVSS 10.0 and rewarded with €1,000.]]></description>
        </item>
        <item>
            <title><![CDATA[Unauthenticated PL/SQL Injection via a Package-Name Parameter (Oracle, error-based)]]></title>
            <link>https://academy.logicalbreach.com//writeups/unauthenticated-pl-sql-injection-via-a-package-name-parameter-oracle-error-based-42826779</link>
            <guid isPermaLink="false">feeec660-cd3d-404c-b312-4b9567009e47</guid>
            <pubDate>Thu, 16 Jul 2026 14:23:23 GMT</pubDate>
            <description><![CDATA[A WebSSO path-normalization bypass (static-asset extension + %2e%2e) exposed a legacy connector's executor servlet, which concatenates a request parameter verbatim as a PL/SQL package name → unauthenticated arbitrary PL/SQL execution on production Oracle (error-based cross-schema read + reversible write proof). ]]></description>
        </item>
        <item>
            <title><![CDATA[Unauthenticated Error-Based SQL Injection via an Identity Header (SiteMinder SM_USER) ]]></title>
            <link>https://academy.logicalbreach.com//writeups/unauthenticated-error-based-sql-injection-via-an-identity-header-siteminder-sm-user-975333f3</link>
            <guid isPermaLink="false">eb11cba0-0288-44e6-b026-871cc81dce67</guid>
            <pubDate>Tue, 14 Jul 2026 10:36:13 GMT</pubDate>
            <description><![CDATA[A critical SQL injection vulnerability in an authentication endpoint allows attackers to execute arbitrary SQL commands, access sensitive data, and manipulate the database.]]></description>
        </item>
        <item>
            <title><![CDATA[[Duplicate] Reflected XSS in Import Map Overrides Enables Account Takeover]]></title>
            <link>https://academy.logicalbreach.com//writeups/reflected-xss-in-import-map-overrides-enables-account-takeover-212e75e5</link>
            <guid isPermaLink="false">579e7431-7811-434f-a798-5db195dc84de</guid>
            <pubDate>Wed, 08 Jul 2026 17:43:31 GMT</pubDate>
            <description><![CDATA[A reflected XSS vulnerability in the import map overrides feature allows attackers to execute arbitrary JavaScript in authenticated user contexts, risking account takeover and credential theft.]]></description>
        </item>
        <item>
            <title><![CDATA[[Duplicate] Unauthorized Access to PII via Improper Authentication in Registration Endpoint]]></title>
            <link>https://academy.logicalbreach.com//writeups/unauthorized-access-to-pii-via-improper-authentication-in-registration-endpoint-b03c7a9b</link>
            <guid isPermaLink="false">b93f7290-df71-4915-9418-2cebc5dda733</guid>
            <pubDate>Wed, 08 Jul 2026 17:41:11 GMT</pubDate>
            <description><![CDATA[An improper authentication flaw in the registration endpoint allows attackers to obtain a session token without credentials, enabling unauthorized access to sensitive personal information such as full name, birth date, and address.]]></description>
        </item>
        <item>
            <title><![CDATA[[Duplicate] DOM XSS in Charting Service's URL Parameter Enables Phishing]]></title>
            <link>https://academy.logicalbreach.com//writeups/dom-xss-in-charting-service-s-url-parameter-enables-phishing-bd379e36</link>
            <guid isPermaLink="false">8639e0ee-a1c6-4eb3-a682-6bfa282ea83f</guid>
            <pubDate>Wed, 08 Jul 2026 17:38:56 GMT</pubDate>
            <description><![CDATA[A DOM-based XSS vulnerability in the widgetScriptUrl parameter of a charting service allows execution of arbitrary JavaScript, enabling phishing attacks to capture user credentials and potentially take over accounts.]]></description>
        </item>
        <item>
            <title><![CDATA[[Duplicate] Reflected XSS in Chart Widget via connectorUrl Parameter]]></title>
            <link>https://academy.logicalbreach.com//writeups/reflected-xss-in-chart-widget-via-connectorurl-parameter-ceb5bf74</link>
            <guid isPermaLink="false">5c96825a-90da-4c94-b6a6-d54b65432c5f</guid>
            <pubDate>Wed, 08 Jul 2026 17:06:07 GMT</pubDate>
            <description><![CDATA[A reflected XSS vulnerability in the chart widget's connectorUrl parameter allows attackers to execute arbitrary JavaScript, potentially leading to credential phishing attacks on users.]]></description>
        </item>
        <item>
            <title><![CDATA[[CVE-2026-40762] Unauthenticated SQL Injection in WPGraphQL < 2.11.1]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-40762-unauthenticated-sql-injection-in-wpgraphql-2-11-1-f85ad3b3</link>
            <guid isPermaLink="false">429cb620-d596-4b9b-8c73-9a8cd42df69b</guid>
            <pubDate>Wed, 08 Jul 2026 09:51:31 GMT</pubDate>
            <description><![CDATA[An unauthenticated time-based blind SQL injection was confirmed in a public WPGraphQL `node(id:)` resolver affected by CVE-2026-40762. The issue was triggered by passing a crafted base64 Relay global ID that decoded to a malicious `user:<value>` identifier and reached a MySQL query path.]]></description>
        </item>
        <item>
            <title><![CDATA[Improper Access Control via Public API Key leads to Mass PII Disclosure]]></title>
            <link>https://academy.logicalbreach.com//writeups/improper-access-control-via-public-api-key-leads-to-mass-pii-disclosure-e3ccd56e</link>
            <guid isPermaLink="false">214a9016-72bf-4722-8a76-4fb5b1413dcc</guid>
            <pubDate>Mon, 06 Jul 2026 13:56:11 GMT</pubDate>
            <description><![CDATA[An unauthenticated PII disclosure issue was found in a public web portal backed by a production API gateway. The frontend exposed a public gateway key, and a pre-auth user lookup endpoint trusted that key while returning full user records for a broad email search instead of a masked or boolean response.

A single unauthenticated request could return approximately 1.6k user records, including names, email addresses, internal user IDs and mobile phone numbers. The issue was accepted as High severity with CVSS 7.5 and rewarded with €400.]]></description>
        </item>
        <item>
            <title><![CDATA[Improper Access Control via Client-Supplied Document Identifier Leads to PII Disclosure]]></title>
            <link>https://academy.logicalbreach.com//writeups/improper-access-control-via-client-supplied-document-identifier-leads-to-pii-disclosure-29367c5a</link>
            <guid isPermaLink="false">4d265d0a-f2b3-4428-9b07-6f9382c403b3</guid>
            <pubDate>Fri, 03 Jul 2026 14:58:24 GMT</pubDate>
            <description><![CDATA[An unauthenticated Improper Access Control vulnerability was identified in a public mobile onboarding API. A registration action accepted a client-controlled document identifier and returned the associated identity profile without requiring a valid session, authorization token, or onboarding token.]]></description>
        </item>
        <item>
            <title><![CDATA[Path Traversal via an unauthenticated export/download action using client-controlled directory and filename parameters]]></title>
            <link>https://academy.logicalbreach.com//writeups/path-traversal-via-an-unauthenticated-export-download-action-using-client-controlled-directory-and-filename-parameters-a9c49b9e</link>
            <guid isPermaLink="false">92fd26df-8c0f-4adb-a9bc-abc0c3e27bf3</guid>
            <pubDate>Tue, 30 Jun 2026 15:56:29 GMT</pubDate>
            <description><![CDATA[An unauthenticated arbitrary file read vulnerability was identified in a public legacy web portal. A download/export action accepted client-controlled parameters for both the target directory and file name, allowing the backend to return local server files without proper validation, allowlisting, or path canonicalization.]]></description>
        </item>
        <item>
            <title><![CDATA[POST-Based XSS Using Octal Escapes]]></title>
            <link>https://academy.logicalbreach.com//writeups/post-based-xss-using-octal-escapes-51f1aab9</link>
            <guid isPermaLink="false">f589d1de-a1f1-4e61-816e-aece5bdb4ae7</guid>
            <pubDate>Fri, 26 Jun 2026 12:00:12 GMT</pubDate>
            <description><![CDATA[Bypassing XSS security using octal encoding]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-12064: proto-default skips SSH verification]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-12064-proto-default-skips-ssh-verification-204ef8ee</link>
            <guid isPermaLink="false">41bfddbe-d4f0-4da9-9b5f-647af831ce62</guid>
            <pubDate>Wed, 24 Jun 2026 08:29:28 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3797526 by alienowo]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-11586: WS Auto-PONG memory exhaustion]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-11586-ws-auto-pong-memory-exhaustion-7ef6089f</link>
            <guid isPermaLink="false">8164da75-5dec-4969-b309-89213ee8f599</guid>
            <pubDate>Wed, 24 Jun 2026 08:29:15 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3788931 by evergarden1123]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8924: trailing dot domain super cookie]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8924-trailing-dot-domain-super-cookie-139be04c</link>
            <guid isPermaLink="false">c59efc5f-8a1d-4384-9449-760e967a9240</guid>
            <pubDate>Wed, 24 Jun 2026 08:28:44 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3733905 by vegagent]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-9546: sending old referer]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-9546-sending-old-referer-3443496d</link>
            <guid isPermaLink="false">6d6e4d88-969b-4b37-a128-33cfdd3b6743</guid>
            <pubDate>Wed, 24 Jun 2026 08:27:22 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3754343 by fafawf]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-9079: stale proxy password leak]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-9079-stale-proxy-password-leak-9dada8bb</link>
            <guid isPermaLink="false">9fe5faf9-d38e-47cb-8baf-9638c9884ce7</guid>
            <pubDate>Wed, 24 Jun 2026 08:26:56 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3750295 by keen4n]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-9080: UAF after pause in socket callback]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-9080-uaf-after-pause-in-socket-callback-1308e440</link>
            <guid isPermaLink="false">8d7350e0-6624-4e83-a8d2-215810ed4438</guid>
            <pubDate>Wed, 24 Jun 2026 08:25:17 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3749204 by giant_anteater]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8932: incomplete mTLS config matching in conn reuse]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8932-incomplete-mtls-config-matching-in-conn-reuse-93418df6</link>
            <guid isPermaLink="false">730287fe-c3f5-4611-a0e5-fe7303c9d37c</guid>
            <pubDate>Wed, 24 Jun 2026 08:25:03 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3733910 by giant_anteater]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8927: env-set cross-proxy Digest auth state leak]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8927-env-set-cross-proxy-digest-auth-state-leak-d7ef4fa7</link>
            <guid isPermaLink="false">cd7c4e58-523c-49b2-807f-12bc13d060ff</guid>
            <pubDate>Wed, 24 Jun 2026 08:24:47 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3744543 by adyej]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8925: SASL double-free]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8925-sasl-double-free-41c92280</link>
            <guid isPermaLink="false">771907ac-5178-4b01-b1f0-5cfaaa1d8aa3</guid>
            <pubDate>Wed, 24 Jun 2026 08:23:35 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3735193 by giant_anteater]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8926: password leak with netrc and user in URL]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8926-password-leak-with-netrc-and-user-in-url-6c2e0dc5</link>
            <guid isPermaLink="false">82a733f7-048d-499d-9130-7944bc9a0618</guid>
            <pubDate>Wed, 24 Jun 2026 08:23:22 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3735184 by giant_anteater]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-8458: wrong reuse for different services]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-8458-wrong-reuse-for-different-services-0ca242a7</link>
            <guid isPermaLink="false">7b4ca2ac-0761-43a7-a104-85d7e88df436</guid>
            <pubDate>Wed, 24 Jun 2026 08:23:10 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3721183 by areksaxyz]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-9545: exposing HTTP/3 early data]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-9545-exposing-http-3-early-data-75ab63c3</link>
            <guid isPermaLink="false">ada6a82e-4510-452a-b36a-3258b293f33e</guid>
            <pubDate>Wed, 24 Jun 2026 06:24:17 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3752888 by hahahkim]]></description>
        </item>
        <item>
            <title><![CDATA[CVE-2026-11856: cross-origin Digest auth state leak]]></title>
            <link>https://academy.logicalbreach.com//writeups/cve-2026-11856-cross-origin-digest-auth-state-leak-ad2b7af3</link>
            <guid isPermaLink="false">18e75e38-298c-4c9d-80d6-e039635f53bc</guid>
            <pubDate>Wed, 24 Jun 2026 06:21:56 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3793260 by jjchuck]]></description>
        </item>
        <item>
            <title><![CDATA[Taskcluster web-server OAuth2 authorization codes are reusable and the exchange handler checks the wrong expiry column]]></title>
            <link>https://academy.logicalbreach.com//writeups/taskcluster-web-server-oauth2-authorization-codes-are-reusable-and-the-exchange-handler-checks-the-wrong-expiry-column-3cdf46bf</link>
            <guid isPermaLink="false">2cc5d9f0-4647-48ae-a910-850a87896450</guid>
            <pubDate>Tue, 23 Jun 2026 12:37:52 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3734676 by anshuman_bh]]></description>
        </item>
        <item>
            <title><![CDATA[1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation]]></title>
            <link>https://academy.logicalbreach.com//writeups/1-click-account-takeover-via-open-redirect-through-regex-bypass-in-domain-validation-4152a0e1</link>
            <guid isPermaLink="false">02b87d5f-529f-470d-aa74-6a1db7bc122a</guid>
            <pubDate>Sat, 20 Jun 2026 15:58:07 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3723458 by farr]]></description>
        </item>
        <item>
            <title><![CDATA[Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering]]></title>
            <link>https://academy.logicalbreach.com//writeups/reflected-xss-in-ai-chat-bot-greetings-at-help-shopify-com-via-markdown-image-rendering-dba93ba5</link>
            <guid isPermaLink="false">4bc4b6b9-ec9a-45af-9937-40cb9588b823</guid>
            <pubDate>Thu, 18 Jun 2026 12:48:02 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/2509022 by saltymermaid]]></description>
        </item>
        <item>
            <title><![CDATA[Authenticated Elasticsearch Painless script execution via Query.search.sort_query on hackerone.com/graphql]]></title>
            <link>https://academy.logicalbreach.com//writeups/authenticated-elasticsearch-painless-script-execution-via-query-search-sort-query-on-hackerone-com-graphql-0e9e43e7</link>
            <guid isPermaLink="false">d7983a88-8380-4729-8704-91a5484f49f8</guid>
            <pubDate>Wed, 17 Jun 2026 14:17:26 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3694007 by brumbelow]]></description>
        </item>
        <item>
            <title><![CDATA[Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown]]></title>
            <link>https://academy.logicalbreach.com//writeups/malicious-conflux-endpoint-can-leave-stale-global-ooo-queue-accounting-after-teardown-a766f087</link>
            <guid isPermaLink="false">88081149-c9aa-4f2f-946d-c482c56276d9</guid>
            <pubDate>Tue, 16 Jun 2026 07:16:47 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3701692 by aptupdate]]></description>
        </item>
        <item>
            <title><![CDATA[Burp Suite Professional: browser-powered crawl can write attacker-controlled files through file input handling]]></title>
            <link>https://academy.logicalbreach.com//writeups/burp-suite-professional-browser-powered-crawl-can-write-attacker-controlled-files-through-file-input-handling-4a6c87e7</link>
            <guid isPermaLink="false">51eb997f-2e42-4a75-a65d-35dfa68d90de</guid>
            <pubDate>Sun, 14 Jun 2026 08:08:52 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3712279 by kawakatz]]></description>
        </item>
        <item>
            <title><![CDATA[Command Injection via Unsanitized Bundling Options in `aws-cdk-lib/aws-lambda-nodejs`]]></title>
            <link>https://academy.logicalbreach.com//writeups/command-injection-via-unsanitized-bundling-options-in-aws-cdk-lib-aws-lambda-nodejs-ab1f3c90</link>
            <guid isPermaLink="false">706dc85d-bf70-4974-af76-d954f355b8b8</guid>
            <pubDate>Thu, 11 Jun 2026 16:54:20 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3558713 by inkerton]]></description>
        </item>
        <item>
            <title><![CDATA[SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function]]></title>
            <link>https://academy.logicalbreach.com//writeups/ssrf-via-improper-redirect-validation-in-rocket-chat-oembed-function-9647fc33</link>
            <guid isPermaLink="false">30b21de7-1d40-47e9-83c4-fe22da93e337</guid>
            <pubDate>Thu, 11 Jun 2026 11:52:32 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3383079 by button142857]]></description>
        </item>
        <item>
            <title><![CDATA[SSRF via improper validation after DNS name resolution in the link-preview feature]]></title>
            <link>https://academy.logicalbreach.com//writeups/ssrf-via-improper-validation-after-dns-name-resolution-in-the-link-preview-feature-6463037a</link>
            <guid isPermaLink="false">04b7a1a3-ec72-44e2-9734-bcce2a57eeeb</guid>
            <pubDate>Thu, 11 Jun 2026 11:52:25 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3393664 by button142857]]></description>
        </item>
        <item>
            <title><![CDATA[Action Text ReDoS (Ruby 3.1  or lower)]]></title>
            <link>https://academy.logicalbreach.com//writeups/action-text-redos-ruby-3-1-or-lower-170d95f9</link>
            <guid isPermaLink="false">082ed25a-639c-4a0e-8e8a-affefef19891</guid>
            <pubDate>Tue, 09 Jun 2026 04:37:55 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/2389431 by ooooooo_q]]></description>
        </item>
        <item>
            <title><![CDATA[DLL side-loading vulnerability in Sony Music Center for PC Ver. 2.7.2 (Latest version)]]></title>
            <link>https://academy.logicalbreach.com//writeups/dll-side-loading-vulnerability-in-sony-music-center-for-pc-ver-2-7-2-latest-version-17dec387</link>
            <guid isPermaLink="false">d31e5ce7-d3da-4924-8071-65cd06cc082f</guid>
            <pubDate>Fri, 05 Jun 2026 09:10:24 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3355766 by resurrect20]]></description>
        </item>
        <item>
            <title><![CDATA[DLL side-loading vulnerability in Sony Music Center for PC Ver. 2.7.2 (Latest version)]]></title>
            <link>https://academy.logicalbreach.com//writeups/dll-side-loading-vulnerability-in-sony-music-center-for-pc-ver-2-7-2-latest-version-941b1260</link>
            <guid isPermaLink="false">bbee4e32-4d6c-4bd5-a72f-aff019c4bedd</guid>
            <pubDate>Fri, 05 Jun 2026 09:10:24 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3355766 by resurrect20]]></description>
        </item>
        <item>
            <title><![CDATA[Hardcoded Authentication Token in Public JS → Admin API Session Takeover]]></title>
            <link>https://academy.logicalbreach.com//writeups/hardcoded-authentication-token-in-public-js-admin-api-session-takeover-0d9d0d46</link>
            <guid isPermaLink="false">0f5df200-0d17-4e56-a886-6e2da285b208</guid>
            <pubDate>Fri, 05 Jun 2026 08:23:26 GMT</pubDate>
            <description><![CDATA[Hardcoded admin token in public JS → unauthenticated admin API session → live tampering of 774 public form labels (legal/payment/support text) on a government portal, plus AES password-encryption key disclosure.]]></description>
        </item>
        <item>
            <title><![CDATA[Improper Access Control on www.target.example through /services/formcampaign via header "option" leads to unauthenticated read/write on the production marketing-campaign database]]></title>
            <link>https://academy.logicalbreach.com//writeups/improper-access-control-on-www-target-example-through-services-formcampaign-via-header-option-leads-to-unauthenticated-read-write-on-the-production-marketing-campaign-database-b84f1127</link>
            <guid isPermaLink="false">e6b2303c-ba46-4e14-8e41-11eef60d83f6</guid>
            <pubDate>Mon, 01 Jun 2026 09:09:18 GMT</pubDate>
            <description><![CDATA[An unauthenticated AEM Sling servlet exposes four CRUD operations (getData / getDataById / setData / updateData) on the internal marketing-campaign database via a single option request header. The only access control is a Referer string check that any HTTP client trivially bypasses. Anonymous attackers can read the full 79-campaign dataset (including internal segmentation logic and the names of internal prospect databases), create arbitrary new campaigns in the production backoffice, and overwrite existing real production campaigns.]]></description>
        </item>
        <item>
            <title><![CDATA[Stored XSS in public-share preview silently exposes the victim's entire drive]]></title>
            <link>https://academy.logicalbreach.com//writeups/stored-xss-in-public-share-preview-silently-exposes-the-victim-s-entire-drive-e63671bc</link>
            <guid isPermaLink="false">c48aa92f-f865-4885-9e97-00e8bec33ae7</guid>
            <pubDate>Mon, 01 Jun 2026 09:01:59 GMT</pubDate>
            <description><![CDATA[Stored XSS on a cloud-drive public-share preview endpoint that serves user-uploaded HTML as text/html on the main application origin with a permissive CSP. A single click on the share link executes attacker JavaScript with same-origin access to the victim's session, allowing the attacker to impersonate the victim against every drive API — exfiltrating collaborator PII, the full file tree, payment-system identifiers and five cross-service XSRF tokens, modifying account preferences, and silently turning every private file in the victim's drive into a public URL.]]></description>
        </item>
        <item>
            <title><![CDATA[Blind POST SSRF via Web Push Notification Endpoint]]></title>
            <link>https://academy.logicalbreach.com//writeups/blind-post-ssrf-via-web-push-notification-endpoint-3e0fc1d7</link>
            <guid isPermaLink="false">303c963f-802d-4d16-a0f9-5e5c6ad0f508</guid>
            <pubDate>Sat, 30 May 2026 16:47:37 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3608558 by misop00p]]></description>
        </item>
        <item>
            <title><![CDATA[Email Verification Bypass / Email Squatting via Client-Side `accounts.setAccountInfo`]]></title>
            <link>https://academy.logicalbreach.com//writeups/email-verification-bypass-email-squatting-via-client-side-accounts-setaccountinfo-46c1127b</link>
            <guid isPermaLink="false">5ba3fdc3-573f-48b1-aaaa-fc3ca9f3f6ff</guid>
            <pubDate>Sat, 30 May 2026 14:41:50 GMT</pubDate>
            <description><![CDATA[]]></description>
        </item>
        <item>
            <title><![CDATA[Admin Panel Exposure via WAF Bypass (URL Encoding) + Broken reCAPTCHA + Internal Info Leak]]></title>
            <link>https://academy.logicalbreach.com//writeups/admin-panel-exposure-via-waf-bypass-url-encoding-broken-recaptcha-internal-info-leak-0008950f</link>
            <guid isPermaLink="false">20482471-ba91-4f23-896a-8031f30b93a9</guid>
            <pubDate>Sat, 30 May 2026 14:39:30 GMT</pubDate>
            <description><![CDATA[]]></description>
        </item>
        <item>
            <title><![CDATA[DOM-XSS on Central SSO Origin via Unvalidated `retryUrl` (WAF Bypass with `javascript:name`)]]></title>
            <link>https://academy.logicalbreach.com//writeups/dom-xss-on-central-sso-origin-via-unvalidated-retryurl-waf-bypass-with-javascript-name-ac701cac</link>
            <guid isPermaLink="false">ce375e45-4e79-45ae-bc31-06f134750b58</guid>
            <pubDate>Sat, 30 May 2026 14:35:23 GMT</pubDate>
            <description><![CDATA[Collab with Tonysec

https://academy.logicalbreach.com/authors/tonysec]]></description>
        </item>
        <item>
            <title><![CDATA[ Inventory Disruption via Quantity Manipulation in Order Creation]]></title>
            <link>https://academy.logicalbreach.com//writeups/inventory-disruption-via-quantity-manipulation-in-order-creation-99c02266</link>
            <guid isPermaLink="false">0d7016bb-62f1-4195-97cd-324aed48fd62</guid>
            <pubDate>Sat, 30 May 2026 14:32:15 GMT</pubDate>
            <description><![CDATA[]]></description>
        </item>
        <item>
            <title><![CDATA[Payment Method Validation Bypass via Order Update Flow]]></title>
            <link>https://academy.logicalbreach.com//writeups/payment-method-validation-bypass-via-order-update-flow-0f9955f9</link>
            <guid isPermaLink="false">48ee7179-d538-4ecf-8c44-e6dade5a8f63</guid>
            <pubDate>Sat, 30 May 2026 14:28:58 GMT</pubDate>
            <description><![CDATA[]]></description>
        </item>
        <item>
            <title><![CDATA[A PortSwigger-lab-style cache poisoning  → pre-auth ATO with a single request]]></title>
            <link>https://academy.logicalbreach.com//writeups/a-portswigger-lab-style-cache-poisoning-pre-auth-ato-with-a-single-request-6dce8f5e</link>
            <guid isPermaLink="false">c3d6a5e6-edf4-4d85-9ca6-bd0250b40e41</guid>
            <pubDate>Sat, 30 May 2026 10:19:44 GMT</pubDate>
            <description><![CDATA[PortSwigger-lab-style cache poisoning via Referer + Akamai WAF bypass → zero-interaction ATO]]></description>
        </item>
        <item>
            <title><![CDATA[V1Plugin.Decrypt panics on empty ciphertext (Remote DoS)]]></title>
            <link>https://academy.logicalbreach.com//writeups/v1plugin-decrypt-panics-on-empty-ciphertext-remote-dos-2d43856a</link>
            <guid isPermaLink="false">2ebbb2cb-7398-4fcf-b007-927c677a8bac</guid>
            <pubDate>Thu, 28 May 2026 16:40:31 GMT</pubDate>
            <description><![CDATA[HackerOne disclosed report --> https://hackerone.com/reports/3620748 by misop00p]]></description>
        </item>
    </channel>
</rss>