DoS via GraphQL Batching
Application-level denial of service vulnerability via GraphQL batching and resource exhaustion (72x amplification).
Bug Bounty writeups and real-world pentest reports.
Application-level denial of service vulnerability via GraphQL batching and resource exhaustion (72x amplification).
Reflected XSS and HTTP Parameter Pollution in a real e-commerce site, leading to session hijacking and cookie exfiltration.
XSS vulnerability in outdated Bootstrap framework leading to complete account compromise via session hijacking.