antivirus

1 article
sort: new top best
clear filter
0 7/10

Reflected XSS vulnerability in Avast Desktop AntiVirus (and AVG) via unsanitized SSID name reflection in the Firewall's Network Notification feature popup, allowing attackers to execute arbitrary JavaScript through a malicious wireless network name. The vulnerability was discovered by connecting to a tethering connection with an XSS payload SSID and triggered when the notification feature displayed the network name without proper input filtering, earning a $5,000 bounty.

CVE-2019-18653 CVE-2019-18654 Avast AVG YoKo Kho Brute Logic S0md3v Deral Heiland Windows 10 InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details