Sitemap

From CRLF Injection to XSS: Elevating the Stakes in Apple iTunes Security

3 min readFeb 23, 2024

--

Press enter or click to view image in full size
Press enter or click to view image in full size
The Response from the apple subdomain with the cookie was reflected
Press enter or click to view image in full size
The Response from the apple subdomain with the Content-type was reflected

--

--

Khaled Mohamed
Khaled Mohamed

Written by Khaled Mohamed

Bug Hunter || Security Researcher at Hackerone, Detectify Crowdsource, Synack Red Team.