1. Improper Implementation of Implicit Grant
2. Flawed CSRF Protection
3. Flawed Redirect_URI Validation
More difficult:
4. Stealing Codes via a Proxy Page
5. Scope Upgrade of Authorization Code Flow
1. Improper Implementation of Implicit Grant
2. Flawed CSRF Protection
3. Flawed Redirect_URI Validation
More difficult:
4. Stealing Codes via a Proxy Page
5. Scope Upgrade of Authorization Code Flow