Escalating an Out-of-Scope HTML Injection to a Critical 9.3 XSS (WAF Bypass)

medium.com · Hussein Mahmoud · 15 hours ago · vulnerability
0 net

How keeping a browser tab open for 2.5 months helped me bypass a strict WAF using WebKit and String Concatenation.