XSPA / SSRF bug with Facebookâs Developer Web Application May 10, 2013 in bugbounty, research, appsec, cross site port attacks The first XSPA/SSRF bug that led to the discovery of this issue in other applications and eventually a paper that was presented at multiple conferences. Continue reading