accesskey-attribute

4 articles
sort: new top best
clear filter
0 8/10

PortSwigger researchers discovered a practical XSS exploitation technique for hidden input fields using the accesskey attribute combined with onclick events, which works across modern browsers including Firefox and Chrome by triggering payload execution via keyboard shortcuts (ALT+SHIFT+X on Windows, CTRL+ALT+X on macOS).

PortSwigger Burp Suite Gareth Heyes Liam
portswigger.net · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10
bug-bounty

A reflected XSS vulnerability was found on sharjah.dubizzle.com (OLX property) where unsanitized user input was reflected in an HTML link tag. The vulnerability exploited the HTML accesskey attribute combined with onclick handler to execute arbitrary JavaScript when users pressed ALT+SHIFT+X.

OLX Dubizzle Akbar Kustirama HackerOne PortSwigger
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 3/10

A reflected XSS vulnerability was discovered in Oracle NetSuite's search functionality exploiting the HTML accesskey attribute, allowing arbitrary JavaScript execution when a victim pressed Alt+Shift+X on a crafted malicious link.

Oracle NetSuite Circle Ninja search.netsuite.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A detailed writeup presenting five real-world XSS vulnerabilities across different web applications, showcasing evasion techniques including mobile DOM-events not covered by blacklists, hidden input attribute injection, WAF bypass through incomplete tag closure with script src attributes, and the importance of testing overlooked functionality.

Oleksandr Opanasiuk
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details