Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

XSS Using Active Directory Automatic Provisioning

Summary

Azure AD SCIM provisioning synced user names into a web app without output encoding, giving script injection via the firstName field and a path to steal credentials with an imported JS file.
Published
Collected

original ↗