Vulnerabilities Allowed Hackers To Change Passwords Of Tiktok Accounts Cybers Guards
After spotting a pair of glitches that might have been chained to hijack accounts, a researcher won almost $4,000 from TikTok. In late August, Muhammed Taskiran, a 20-year-old German-based researcher, told TikTok that a URL parameter on tiktok.com “reflected its value without being properly sanitized.” This implemented a mirrored cross-site scripting (XSS) vulnerability that may have been related to a Taskiran found cross-site request forgery (CSRF) bug. An endpoint that allowed the researcher to set a new password for accounts that had used third-party applications to sign up to the social media site was affected by the CSRF problem....