credit-card-theft

1 article
sort: new top best
clear filter
0 6/10

Researcher bypassed a WAF filtering angle brackets by inserting dummy tags (e.g., <x>) to obfuscate XSS payloads, then exploited reflected XSS to steal user credit card data via jQuery GET/POST requests to exfiltrate payment details pages.

Osama Avvan Bugcrowd Redact.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details