Yet another reason why Token Exchange is dangerous 🤯😱
"Bing is allowed to issue Office tokens for any logged-on user"
When inspecting Bing requests, I noticed an endpoint being used for Office 365 communications. As it turns out, Bing is allowed to issue Office tokens for any logged-on user. I quickly crafted an XSS payload utilizing this functionality, tested it on myself, and it worked!