0day

1 article
sort: new top best
clear filter
0 6/10

A reflected XSS vulnerability discovered in AMP iframe redirect endpoints across multiple companies (Shopify, Canva, Yelp, Western Union, Cuvva) by bypassing Content Security Policy using JavaScript injection via the redirect_strategy parameter.

Ali TÜTÜNCÜ Shopify Canva Yelp Western Union Cuvva
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details