HackerOne redox_bbp • Unauthenticated Dynamic Client Registration HIGH
POST /platform/v1/oauth/register → 201 with client_id + client_secret
CONFIRMED
10x.redoxengine.com/#/oauth/authorize
POST /platform/v1/oauth/token → access_token + refresh_token
With the captured authorization code, the attacker exchanges it for a platform_access token that inherits the victim's full permissions: