client-side-escaping

1 article
sort: new top best
clear filter
0 7/10

XSS vulnerability in Facebook Studio discovered via incorrect Content-Type header (text/html instead of application/json) that allowed malicious JavaScript to bypass client-side escaping and XSS filters by exploiting content-type sniffing behavior. The vulnerability was fixed by correcting the Content-Type header to application/json.

Facebook Studio Facebook Chrome XSS Auditor IE XSS Filter Jack
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details