Web Application Stored HTML Injection That Leads to Domain Account Takeover
Synack Red Team researcher Metin Yunus Kandemir shows how a stored HTML injection flaw in an internal web application can trigger automatic NTLM authentication and, through NTLM relay to ADCS or LDAP, lead to full domain account takeover, including a real engagement where opening a Microsoft Teams meeting invite alone was enough.


