Power Pages Authenticated CORS Attack
One click reads the signed-in victim's portal credential and Profile data, then performs and restores a harmless Profile change. All evidence remains in this browser.
Target:
https://site-g4ihe.powerappsportals.com/Attack resultNot triggered
Portal bearerNot captured
Authenticated ProfileNot captured
Victim-context writeNot triggered
Victim identity and Profile data
Raw authenticated portal bearer
Complete victim-bound JWT returned by the portal:
Decoded portal-bearer claims
Raw victim-bound anti-forgery token
Reversible write evidence
Complete readable authenticated Profile response
Attack log
Ready. Sign in to the target portal in this browser, then click Trigger Attack.