Loading your training overview …
Go to the AcademySecurity research PoC. Parameters: ?wh=<webhook-uuid> to exfiltrate the
logged-in customer token, and/or ?email=<new-email> to change the victim account e-mail
(full account takeover). Both run automatically on load against akademie.tuv.com if the
visitor is logged in.