How one Parameter Pollution bug left many apps vulnerable to Account Takeovers
INTRO While testing a private bug bounty program that enables users to log in using their social media accounts, I noticed that most of the OAuth flow happened on a completely different domain that...