angularjs

1 article
sort: new top best
clear filter
0 8/10
vulnerability

An XSS vulnerability in Google Code-in exploited improper escaping of user input within JSON data embedded in script tags, where the </script> sequence in user comments terminated the script element prematurely, allowing payload execution. The vulnerability was further exploited via AngularJS template injection ({{1-1}}) to bypass the Content Security Policy.

Google Code-in Google VRP AngularJS Thomas Orlita CVE-2018-x (implied but not explicitly stated)
websecblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details