Open note $1,000 CSRF to Full Account Takeover at Verisign (DomainScope)
Responsible disclosure of a $1,000 CSRF in Verisign DomainScope Google OAuth linking — missing state parameter allowed an attacker to link their Google account to a victim's DomainScope profile and take over the account. …