One-Click account takeover.
When testing for vulnerabilities, testing buttons like "Connect with Google" or "Connect with Facebook" that integrate third-party applications may seem quite straightforward. Typically, these actions send a request to the respective third-party server, which then returns an authorization code. This code is included in an HTTP