bug-bounty498
google349
xss301
microsoft292
facebook262
rce211
exploit199
malware169
apple161
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
react52
access-control52
input-validation49
cross-site-scripting48
cloudflare47
aws47
web-security46
lfi46
docker46
sql-injection45
smart-contract45
ethereum44
web-application44
ctf43
oauth43
defi43
web343
node42
pentest39
open-source39
race-condition39
cloud37
idor37
info-disclosure36
burp-suite36
auth-bypass35
0
7/10
vulnerability
Reflected XSS vulnerability in Avast Desktop AntiVirus (and AVG) via unsanitized SSID name reflection in the Firewall's Network Notification feature popup, allowing attackers to execute arbitrary JavaScript through a malicious wireless network name. The vulnerability was discovered by connecting to a tethering connection with an XSS payload SSID and triggered when the notification feature displayed the network name without proper input filtering, earning a $5,000 bounty.
xss
reflected-xss
antivirus
avast
avg
ssid
wifi
windows
payload
bug-bounty
vulnerability-disclosure
cve-2019-18653
cve-2019-18654
firewall
notification
input-validation
code-execution
CVE-2019-18653
CVE-2019-18654
Avast
AVG
YoKo Kho
Brute Logic
S0md3v
Deral Heiland
Windows 10
InfoSec Write-ups