ajax-injection

1 article
sort: new top best
clear filter
0 6/10

XSS vulnerability in dynamically generated JavaScript file endpoint that accepts unsanitized user input via a callback parameter and lacks proper content-type headers, allowing injection of arbitrary JavaScript code that executes in the context of the target domain.

Arbaz Hussain parameth Hurricane Labs Google Gruyere
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details