Anh Tieu
@anhtieuvn
Another cybersecurity researcher. 🇻🇳
ID: 2428970785
05-04-2014 14:07:53
218 Tweet
379 Takipçi
1,1K Takip Edilen
I found 2 stored XSS vulnerabilities in ChatGPT. The XSS bug was the easy part, but sharing it required bypassing CSP, leveraging a mass assignment issue for client-side path traversal (thanks Critical Thinking - Bug Bounty Podcast) to force a request to a BFLA endpoint. 🧵 [1/5]