Abandoned reply URL in Azure AD app could let attackers gain privileges to launch attacks

Within 24 hours of being notified by Secureworks in early April, Microsoft removed the abandoned reply URL from the Azure AD app.

Article Link: Abandoned reply URL in Azure AD app could let attackers gain privileges to launch attacks | SC Media