Image Injection vulnerability on screenshot-viewer/responsive/image may allow Facebook OAuth token theft.

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Image Injection vulnerability on screenshot-viewer/responsive/image may allow Facebook OAuth token theft.

Post by Shane1145 »

In this report, the researcher identified a series of vulnerabilities that could be exploited together to exfiltrate sensitive user tokens. In this attack chain, one critical step was an image injection vulnerability in the Screenshot-Viewer function on the main site, at https://www.rockstargames.com/screensho ... sive/image. We resolved this vulnerability, thus preventing the attack and protecting user tokens.


https://hackerone.com/reports/655288
Post Reply