Cross-origin data disclosure → account takeover — fully one-click PoC
Attacker origin: · injected origin: cp-common.toyota-europe.com · SSO API: ssoms.toyota-europe.com
This runs automatically on page load. Opening the link is the entire interaction. It reads the visitor's
Toyota SSO session and profile, then sets the account password to the value in the ?offer= parameter of
this URL. The target is derived from the session (idFromSession), so it can only ever affect the account
this browser is signed into. The log below is shown for triage. Test on a disposable account.
Log