@ Symbol Turned Into a 1-Click Account TakeoverOAuth redirect_uri bypass via RFC 3986 userinfo component leads to silent token theft via postMessage.
How we found LFI, stored XSS chains, and full account takeover in Adobe Workfront.
An IDOR hunt that took some unexpected turns. Sometimes the simplest bugs are the hardest to pin down.