(May 4, 2022, 07:22 PM)Internetdreams Wrote: yep then you can use the xss on graph.htb?redirect= to exfil tokens of admin through the messages panel and then exploit ffmpeg localfile read to get user ssh
Can you please tell a few more details?
I can make the server send requests to me. When I point to graph.htb?redirect=http://myip the referer is graph.htb but how to exploit that to get the cookie/token?