Yet another reason why Token Exchange is dangerous 馃く馃槺
"Bing is allowed to issue Office tokens for any logged-on user"
When inspecting Bing requests, I noticed an endpoint being used for Office 365 communications. As it turns out, Bing is allowed to issue Office tokens for any logged-on user. I quickly crafted an XSS payload utilizing this functionality, tested it on myself, and it worked!
Mar 30, 2023 路 12:54 AM UTC
2
1
11



