Phantomfeed - HTB University CTF 2023 Winters 2023-12-16 Web tl;dr Leak JWT token through Race Condition. Leak authorization token via an open redirect. Chaining XSS & CSRF in the oauth pipeline to leak the Admin’s oauth access token. RCE via CVE-2023-33733. Read More Race Condition HTBUniversityCTF Oauth RCE Web